Keycloak is an open-source identity and access management solution. A vulnerability was discovered where a user with the impersonation role can impersonate a realm administrator. This allows the attacker to gain full administrative control over the realm, including the ability to manage users, clients, and roles.
References
Configurations
No configuration.
History
16 Sep 2026, 16:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-09-16 16:17
Updated : 2026-09-16 19:42
NVD link : CVE-2026-17526
Mitre link : CVE-2026-17526
CVE.ORG link : CVE-2026-17526
JSON object : View
Products Affected
No product.
CWE
CWE-862
Missing Authorization
