CVE-2026-97177

6.6

Red Hat · Red Hat Build of Keycloak

A missing authorization flaw in the Keycloak Admin REST API allows delegated administrators to bypass password reset restrictions during user profile updates.

Executive summary

A critical authorization bypass vulnerability in the Red Hat Build of Keycloak allows restricted administrative accounts to perform unauthorized password resets, leading to full account takeover.

Vulnerability

This is a missing authorization vulnerability (CWE-862) occurring within the Keycloak Admin REST API. When Fine-Grained Admin Permissions are active, the system fails to validate authorization for password resets during standard user profile updates, allowing an authenticated delegated administrator to elevate their privileges to change user credentials.

Business impact

The ability for a delegated administrator to reset user passwords without proper authorization poses a severe risk to identity and access management security. Successful exploitation could lead to unauthorized access to sensitive user accounts, data exposure, and potential lateral movement within the enterprise environment. While the CVSS score of 6.6 reflects a requirement for high privileges, the impact on authentication integrity is substantial and necessitates immediate attention.

Remediation

Immediate Action: Update the Red Hat Build of Keycloak instance to the latest version provided by the vendor to ensure the authorization check is correctly enforced.

Proactive Monitoring: Review administrative access logs for unusual patterns involving user profile updates or password change requests originating from delegated administrative accounts.

Compensating Controls: Audit and minimize the number of accounts assigned Fine-Grained Admin Permissions until the patch is successfully applied.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the potential for account takeover and the breach of administrative controls, organizations utilizing Red Hat Build of Keycloak or Red Hat Single Sign-On 7 must prioritize this update. Administrators should verify their current version against the official Red Hat security advisory and apply the necessary patches immediately to restore the integrity of the user update mechanism.

More Red Hat CVEs all →

History

  1. Analyst report written

Sources

Originally found and disclosed by Red Hat would like to thank Paul Bottinelli of Trail of Bits in collaboration with OpenAI for reporting this issue., per the CVE Program record.