Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 25 Sep 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Fri, 25 Sep 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in the Fine-Grained Admin Permissions (FGAP v2) feature of Keycloak, an identity and access management solution. The issue occurs when the system checks if a delegated administrator has permission to assign a specific role to a user. Because the check does not look inside composite roles to see what other permissions they contain, an administrator with limited rights can assign a role that secretly includes full administrative control. This allows the attacker to gain complete management access over the entire realm. | |
| Title | Keycloak-services: keycloak-services: fgap v2 composite-blind role mapping allows privilege escalation | |
| First Time appeared |
Redhat
Redhat build Keycloak Redhat red Hat Single Sign On |
|
| Weaknesses | CWE-285 | |
| CPEs | cpe:/a:redhat:build_keycloak: cpe:/a:redhat:red_hat_single_sign_on:7 |
|
| Vendors & Products |
Redhat
Redhat build Keycloak Redhat red Hat Single Sign On |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-09-25T07:39:51.903Z
Reserved: 2026-09-23T09:42:55.806Z
Link: CVE-2026-96448
No data.
Status : Awaiting Analysis
Published: 2026-09-25T08:16:42.437
Modified: 2026-09-25T13:26:09.190
Link: CVE-2026-96448
OpenCVE Enrichment
Updated: 2026-09-25T09:45:17Z
-
CWE-285
Improper Authorization