CVE-2026-17526: Missing Authorization in Red Hat Red Hat build of Keycloak 26.4
Keycloak is an open-source identity and access management solution. A vulnerability was discovered where a user with the impersonation role can impersonate a realm administrator. This allows the attacker to gain full administrative control over the realm, including the ability to manage users, clients, and roles.
AI Analysis
Technical Summary
CVE-2026-17526 is a missing authorization vulnerability in Red Hat build of Keycloak 26.4 that allows a user possessing the impersonation role to escalate privileges by impersonating a realm administrator. This flaw enables the attacker to fully control the realm, including user, client, and role management. Red Hat has issued security advisories (RHSA-2026:68276 and RHSA-2026:68277) releasing fixed container images for Keycloak 26.4.16 and 26.6.7, which include patches for this vulnerability among others. The vulnerability has a CVSS 3.1 base score of 7.2 (high severity) with network attack vector, low attack complexity, high privileges required, no user interaction, and impacts confidentiality, integrity, and availability.
Potential Impact
An attacker with the impersonation role can fully take over a realm administrator account, gaining complete administrative control over the Keycloak realm. This includes the ability to manage users, clients, and roles, potentially compromising the entire identity and access management environment.
Mitigation Recommendations
Red Hat has released fixed container images for Red Hat build of Keycloak versions 26.4.16 and 26.6.7 that address this vulnerability. Users should update to these versions as soon as possible. Before applying the update, back up existing installations, including applications, configuration files, and databases. No other mitigation or workaround is indicated in the vendor advisories.
CVE-2026-17526: Missing Authorization in Red Hat Red Hat build of Keycloak 26.4
Description
Keycloak is an open-source identity and access management solution. A vulnerability was discovered where a user with the impersonation role can impersonate a realm administrator. This allows the attacker to gain full administrative control over the realm, including the ability to manage users, clients, and roles.
CVSS v3.1
Score 7.2high
Affected software
Red Hat
Red Hat build of Keycloak 26.4
Red Hat
Red Hat build of Keycloak 26.4
Red Hat
Red Hat build of Keycloak 26.4.16
Red Hat
Red Hat build of Keycloak 26.6
Red Hat
Red Hat build of Keycloak 26.6
Red Hat
Red Hat build of Keycloak 26.6.7
Red Hat
Red Hat Data Grid 8
Red Hat
Red Hat JBoss Enterprise Application Platform Expansion Pack
Red Hat
Red Hat Single Sign-On 7
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-17526 is a missing authorization vulnerability in Red Hat build of Keycloak 26.4 that allows a user possessing the impersonation role to escalate privileges by impersonating a realm administrator. This flaw enables the attacker to fully control the realm, including user, client, and role management. Red Hat has issued security advisories (RHSA-2026:68276 and RHSA-2026:68277) releasing fixed container images for Keycloak 26.4.16 and 26.6.7, which include patches for this vulnerability among others. The vulnerability has a CVSS 3.1 base score of 7.2 (high severity) with network attack vector, low attack complexity, high privileges required, no user interaction, and impacts confidentiality, integrity, and availability.
Potential Impact
An attacker with the impersonation role can fully take over a realm administrator account, gaining complete administrative control over the Keycloak realm. This includes the ability to manage users, clients, and roles, potentially compromising the entire identity and access management environment.
Mitigation Recommendations
Red Hat has released fixed container images for Red Hat build of Keycloak versions 26.4.16 and 26.6.7 that address this vulnerability. Users should update to these versions as soon as possible. Before applying the update, back up existing installations, including applications, configuration files, and databases. No other mitigation or workaround is indicated in the vendor advisories.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- redhat
- Date Reserved
- 2026-07-27T08:39:49.751Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/errata/RHSA-2026:68276","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:68277","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:68278","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:68280","vendor":"Red Hat"},{"url":"https://access.redhat.com/security/cve/CVE-2026-17526","vendor":"Red Hat"}]
Threat ID: 6aaabd8e55bf5e2cf5d4750a
Added to database: 09/16/2026, 16:02:22 UTC
Last enriched: 09/16/2026, 16:16:29 UTC
Last updated: 09/16/2026, 17:02:20 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.