High severity7.2NVD Advisory· Published Sep 16, 2026· Updated Sep 16, 2026
CVE-2026-17526
CVE-2026-17526
Description
Keycloak is an open-source identity and access management solution. A vulnerability was discovered where a user with the impersonation role can impersonate a realm administrator. This allows the attacker to gain full administrative control over the realm, including the ability to manage users, clients, and roles.
Affected products
1Patches
Vulnerability mechanics
References
6News mentions
0No linked articles in our index yet.