Medium severity6.5NVD Advisory· Published Jun 30, 2026· Updated Aug 5, 2026
CVE-2026-4629
CVE-2026-4629
Description
A flaw was found in Keycloak. A highly privileged user with manage-clients permission can exploit this vulnerability by injecting a hardcoded role mapper into any client. This action allows the user to bypass existing scope restrictions and inject the realm-admin role into generated tokens, resulting in privilege escalation and full administrative access to the realm.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:redhat:build_of_keycloak:-:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
4- bugzilla.redhat.com/show_bug.cginvdExploitVendor Advisory
- access.redhat.com/security/cve/CVE-2026-4629nvdVendor Advisory
- access.redhat.com/errata/RHSA-2026:50846nvd
- access.redhat.com/errata/RHSA-2026:50847nvd
News mentions
0No linked articles in our index yet.