VYPR
Medium severity5.4NVD Advisory· Published Feb 9, 2026· Updated Apr 15, 2026

CVE-2025-14778

CVE-2025-14778

Description

A flaw was found in Keycloak. A significant Broken Access Control vulnerability exists in the UserManagedPermissionService (UMA Protection API). When updating or deleting a UMA policy associated with multiple resources, the authorization check only verifies the caller's ownership against the first resource in the policy's list. This allows a user (Owner A) who owns one resource (RA) to update a shared policy and modify authorization rules for other resources (e.g., RB) in that same policy, even if those other resources are owned by a different user (Owner B). This constitutes a horizontal privilege escalation.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.keycloak:keycloak-servicesMaven
< 26.2.1326.2.13
org.keycloak:keycloak-servicesMaven
>= 26.5.0, < 26.5.326.5.3
org.keycloak:keycloak-servicesMaven
>= 26.3.0, < 26.4.926.4.9

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

10

News mentions

0

No linked articles in our index yet.