VYPR

Keycloak Admin UI

by Keycloak

CVEs (3)

  • CVE-2026-97177MedSep 24, 2026
    risk 0.43cvss 6.6epss 0.00

    A flaw was found in the user update mechanism of the Keycloak Admin REST API. When Fine-Grained Admin Permissions are enabled, the system fails to check for specific password reset authorizations during a general user profile update. This allows a delegated administrator, who…

  • CVE-2026-17048MedJul 24, 2026
    risk 0.29cvss 5.5epss 0.00

    A flaw was found in the Keycloak Admin REST API, which is used to manage security realms and clients. The issue occurs when the system processes requests for rotated client secrets that are stored in a secure vault. Due to improper boundary enforcement, a delegated administrator…

  • CVE-2026-14209MedJun 30, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was discovered in Keycloak's Admin UI extension that allows certain administrative users to bypass security restrictions. When Fine-Grained Admin Permissions (FGAPv2) are enabled, an administrator who should only be able to search for users (but not view their…