Keycloak Admin REST API Password Reset Bypass via User Update
CVE-2026-97177 Published on September 24, 2026
Keycloak-services: keycloak-services: generic user update bypasses denied reset-password permission
A flaw was found in the user update mechanism of the Keycloak Admin REST API. When Fine-Grained Admin Permissions are enabled, the system fails to check for specific password reset authorizations during a general user profile update. This allows a delegated administrator, who should be restricted from resetting passwords, to change a user's credentials and take over their account.
Vulnerability Analysis
CVE-2026-97177 can be exploited with network access, and requires user privileges. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to be very high.
Timeline
Reported to Red Hat.
Made public.
Weakness Type
What is an AuthZ Vulnerability?
The software does not perform an authorization check when an actor attempts to access a resource or perform an action.
CVE-2026-97177 has been classified to as an AuthZ vulnerability or weakness.
Products Associated with CVE-2026-97177
stack.watch emails you whenever new vulnerabilities are published in Red Hat Build Keycloak or Red Hat Single Sign On. Just hit a watch button to start following.