VYPR
High severity7.2NVD Advisory· Published Sep 16, 2026· Updated Sep 16, 2026

CVE-2026-17526

CVE-2026-17526

Description

Keycloak is an open-source identity and access management solution. A vulnerability was discovered where a user with the impersonation role can impersonate a realm administrator. This allows the attacker to gain full administrative control over the realm, including the ability to manage users, clients, and roles.

Affected products

1

Patches

Vulnerability mechanics

References

6

News mentions

0

No linked articles in our index yet.