CVE-2026-9795: Keycloak: keycloak: privilege escalation via improper scope mapping enforcement
A flaw was found in Keycloak's Fine-Grained Admin Permissions (FGAPv2) feature. An administrator with limited client management permissions can exploit this vulnerability to assign any realm role, including highly privileged roles, to a client's scope mapping. This bypasses intended security controls, allowing the injected role to be projected into a user's authentication token when they access the modified client. This could lead to unauthorized privilege escalation within the Keycloak realm.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9795?
The severity of CVE-2026-9795 is classified as high, with a score of 7.3.
How can CVE-2026-9795 be exploited?
CVE-2026-9795 can be exploited by an administrator with limited client management permissions to assign any realm role to a client's scope mapping.
What software is affected by CVE-2026-9795?
CVE-2026-9795 affects Keycloak, particularly its Fine-Grained Admin Permissions (FGAPv2) feature.
How do I fix CVE-2026-9795?
To fix CVE-2026-9795, upgrade to the latest version of Keycloak that addresses this vulnerability.
What are the potential impacts of CVE-2026-9795?
The potential impacts of CVE-2026-9795 include unauthorized privilege escalation and bypassing intended security controls.