Unrated severityNVD Advisory· Published Jun 30, 2026· Updated Jul 1, 2026
Keycloak: keycloak: privilege escalation through hardcoded role mapper injection
CVE-2026-4629
Description
A flaw was found in Keycloak. A highly privileged user with manage-clients permission can exploit this vulnerability by injecting a hardcoded role mapper into any client. This action allows the user to bypass existing scope restrictions and inject the realm-admin role into generated tokens, resulting in privilege escalation and full administrative access to the realm.
Affected products
1Patches
Vulnerability mechanics
References
2- access.redhat.com/security/cve/CVE-2026-4629mitrevdb-entryx_refsource_REDHAT
- bugzilla.redhat.com/show_bug.cgimitreissue-trackingx_refsource_REDHAT
News mentions
0No linked articles in our index yet.