Privilege Escalation via Keycloak Admin REST Group-Membership API
CVE-2026-94000 Published on September 19, 2026
Keycloak-services: keycloak-services: delegated admin with manage-users can escalate to realm-admin via group membership
A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution. The issue occurs in the group-membership endpoints where the system fails to check if a group grants administrative privileges before allowing a user to be added. This allows a delegated administrator with limited permissions to add themselves to a high-privilege group, potentially gaining full control over the entire realm.
Vulnerability Analysis
CVE-2026-94000 is exploitable with network access, and requires user privileges. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to be very high.
Timeline
Reported to Red Hat.
Made public.
Weakness Type
What is an AuthZ Vulnerability?
The software does not perform an authorization check when an actor attempts to access a resource or perform an action.
CVE-2026-94000 has been classified to as an AuthZ vulnerability or weakness.
Products Associated with CVE-2026-94000
stack.watch emails you whenever new vulnerabilities are published in Red Hat Build Keycloak or Red Hat Single Sign On. Just hit a watch button to start following.