CVE-2025-7784
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-07-18

Last updated on: 2026-05-06

Assigner: Red Hat, Inc.

Description
A flaw was found in the Keycloak identity and access management system when Fine-Grained Admin Permissions(FGAPv2) are enabled. An administrative user with the manage-users role can escalate their privileges to realm-admin due to improper privilege enforcement. This vulnerability allows unauthorized elevation of access rights, compromising the intended separation of administrative duties and posing a security risk to the realm.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-07-18
Last Modified
2026-05-06
Generated
2026-05-27
AI Q&A
2025-07-18
EPSS Evaluated
2026-05-25
NVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
redhat build_of_keycloak *
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-269 The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability in Keycloak occurs when Fine-Grained Admin Permissions version 2 (FGAPv2) is enabled. An administrative user with the 'manage-users' role can exploit a flaw in the permission enforcement logic to escalate their privileges to 'realm-admin'. This happens because the system does not properly enforce privilege boundaries during role mapping, allowing the user to assign themselves higher privileges unauthorizedly. [1]


How can this vulnerability impact me? :

The vulnerability allows an administrative user with limited permissions to escalate their privileges to full realm administrator. This unauthorized elevation can lead to complete administrative control over the Keycloak realm, including access to sensitive user data and configuration settings, thereby compromising the security and integrity of the system. [1]


How can this vulnerability be detected on my network or system? Can you suggest some commands?

Detection involves monitoring for unauthorized role changes via the Keycloak Admin REST API, specifically looking for users with the 'manage-users' role assigning themselves the 'realm-admin' role. You can audit Keycloak admin logs for suspicious role mapping activities. There are no specific commands provided in the resources, but reviewing audit logs and API request logs for role modifications is recommended. [1]


What immediate steps should I take to mitigate this vulnerability?

Immediate mitigation steps include disabling FGAPv2 (Fine-Grained Admin Permissions version 2) if not required, restricting the 'manage-users' role to trusted administrators only, and applying any available patches or updates from Keycloak that address this privilege escalation flaw. Additionally, closely monitor admin role assignments and audit logs to detect and prevent unauthorized privilege escalations. [1]


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart