<Vulnerability name="CVE-2026-94000">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Moderate</ThreatSeverity>
    <PublicDate>2026-09-18T00:25:25</PublicDate>
    <Bugzilla id="2537168" url="https://bugzilla.redhat.com/show_bug.cgi?id=2537168" xml:lang="en:us">
keycloak-services: keycloak-services: Delegated admin with manage-users can escalate to realm-admin via group membership
    </Bugzilla>
    <CVSS3 status="draft">
        <CVSS3BaseScore>6.6</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-862</CWE>
    <Details xml:lang="en:us" source="Mitre">
A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution. The issue occurs in the group-membership endpoints where the system fails to check if a group grants administrative privileges before allowing a user to be added. This allows a delegated administrator with limited permissions to add themselves to a high-privilege group, potentially gaining full control over the entire realm.
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution. The issue occurs in the group-membership endpoints where the system fails to check if a group grants administrative privileges before allowing a user to be added. This allows a delegated administrator with limited permissions to add themselves to a high-privilege group, potentially gaining full control over the entire realm.
    </Details>
    <Statement xml:lang="en:us">
The Red Hat Product Security team has assessed the severity of this vulnerability as Moderate, given that exploitation requires a specific pre-existing configuration (a group mapping administrative roles) and an attacker already possessing high-level delegated administrative privileges. Successful exploitation allows an attacker to escalate their privileges to realm-admin, gaining full control over the affected realm. The vulnerability's root cause is a failure to validate the administrative implications of group membership changes in the Admin REST API.
    </Statement>
    <Acknowledgement xml:lang="en:us">
Red Hat would like to thank SECTION: Create Trackers {yes for reporting this issue.
    </Acknowledgement>
    <Mitigation xml:lang="en:us">
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
    </Mitigation>
    <PackageState cpe="cpe:/a:redhat:build_keycloak:">
        <ProductName>Red Hat Build of Keycloak</ProductName>
        <FixState>Affected</FixState>
        <PackageName>keycloak/rhbk-openshift-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:build_keycloak:">
        <ProductName>Red Hat Build of Keycloak</ProductName>
        <FixState>Affected</FixState>
        <PackageName>keycloak-services</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:build_keycloak:">
        <ProductName>Red Hat Build of Keycloak</ProductName>
        <FixState>Affected</FixState>
        <PackageName>rhbk/keycloak-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:red_hat_single_sign_on:7">
        <ProductName>Red Hat Single Sign-On 7</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>keycloak-services</PackageName>
    </PackageState>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-94000
https://nvd.nist.gov/vuln/detail/CVE-2026-94000
    </References>
</Vulnerability>