High severity7.3NVD Advisory· Published May 28, 2026· Updated Jul 15, 2026
CVE-2026-9795
CVE-2026-9795
Description
A flaw was found in Keycloak's Fine-Grained Admin Permissions (FGAPv2) feature. An administrator with limited client management permissions can exploit this vulnerability to assign any realm role, including highly privileged roles, to a client's scope mapping. This bypasses intended security controls, allowing the injected role to be projected into a user's authentication token when they access the modified client. This could lead to unauthorized privilege escalation within the Keycloak realm.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.keycloak:keycloak-servicesMaven | < 26.6.4 | 26.6.4 |
Affected products
3(expand)+ 1 more
- (no CPE)
- cpe:2.3:a:redhat:build_of_keycloak:-:*:*:*:-:*:*:*
Patches
Vulnerability mechanics
References
13- access.redhat.com/security/cve/CVE-2026-9795nvdMitigationVendor AdvisoryWEB
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingVendor AdvisoryWEB
- github.com/advisories/GHSA-32h4-44jj-c5vxghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-9795ghsaADVISORY
- access.redhat.com/errata/RHSA-2026:30049nvdWEB
- access.redhat.com/errata/RHSA-2026:30050nvdWEB
- access.redhat.com/errata/RHSA-2026:30083nvdWEB
- access.redhat.com/errata/RHSA-2026:30084nvdWEB
- github.com/keycloak/keycloak/commit/8894c027e788904c740ff9a1a60fcfaa34a10d13ghsaWEB
- github.com/keycloak/keycloak/issues/50350ghsaWEB
- github.com/keycloak/keycloak/pull/50451ghsaWEB
- github.com/keycloak/keycloak/security/advisories/GHSA-32h4-44jj-c5vxghsaWEB
- security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-9795.jsonnvdWEB
News mentions
1- Keycloak: Twelve Vulnerabilities Disclosed, One High SeverityVypr Intelligence · May 28, 2026