VYPR
Unrated severityNVD Advisory· Published Jun 30, 2026· Updated Jul 1, 2026

Keycloak: keycloak: privilege escalation through hardcoded role mapper injection

CVE-2026-4629

Description

A flaw was found in Keycloak. A highly privileged user with manage-clients permission can exploit this vulnerability by injecting a hardcoded role mapper into any client. This action allows the user to bypass existing scope restrictions and inject the realm-admin role into generated tokens, resulting in privilege escalation and full administrative access to the realm.

Affected products

1

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.