Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…
EPSS 0.5%top 62%

CVE-2026-3121: Incorrect Privilege Assignment in Red Hat Red Hat build of Keycloak 26.4

0
Medium
VulnerabilityCVE-2026-3121cvecve-2026-3121
Published: 03/26/2026 (03/26/2026, 19:13:26 UTC)
Source: CVE Database V5
Vendor/Project: Red Hat
Product: Red Hat build of Keycloak 26.4

Description

A flaw was found in Keycloak. An administrator with `manage-clients` permission can exploit a misconfiguration where this permission is equivalent to `manage-permissions`. This allows the administrator to escalate privileges and gain control over roles, users, or other administrative functions within the realm. This privilege escalation can occur when admin permissions are enabled at the realm level.

CVSS v3.1

Score 6.5medium

Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 04/03/2026, 03:21:03 UTC

Technical Analysis

CVE-2026-3121 identifies a security vulnerability in Red Hat's build of Keycloak version 26.4, specifically involving incorrect privilege assignment. Keycloak is an open-source identity and access management solution widely used for single sign-on and authentication services. The vulnerability stems from a misconfiguration where the 'manage-clients' permission is effectively treated as equivalent to the 'manage-permissions' permission at the realm level. Normally, 'manage-clients' allows administrators to manage client applications, while 'manage-permissions' grants broader control over roles, users, and other administrative functions. Due to this flaw, an administrator with only 'manage-clients' permission can escalate privileges to gain unauthorized control over sensitive administrative capabilities within the realm. This escalation can compromise the confidentiality and integrity of the identity management system, potentially allowing unauthorized modification of user roles, permissions, and access controls. The vulnerability requires the attacker to have some administrative privileges (high privileges) but does not require user interaction, and it can be exploited remotely over the network. The CVSS v3.1 base score of 6.5 reflects a medium severity rating, with high impact on confidentiality and integrity but no impact on availability. No public exploits have been reported yet, but the flaw poses a significant risk in environments where realm-level administrative permissions are enabled and misconfigured. The vulnerability highlights the importance of strict permission separation and careful configuration in identity management systems. Organizations using this Keycloak build should monitor for patches and review their permission assignments to prevent privilege escalation.

Potential Impact

The primary impact of CVE-2026-3121 is unauthorized privilege escalation within Keycloak realms, which can lead to compromise of identity and access management controls. An attacker with 'manage-clients' permission can gain broader administrative rights, potentially modifying user roles, permissions, and access policies. This undermines the confidentiality and integrity of the authentication system, risking unauthorized access to sensitive applications and data protected by Keycloak. Although availability is not directly affected, the breach of administrative controls can facilitate further attacks or persistent unauthorized access. Organizations relying on Keycloak for critical authentication services, especially those with complex realm-level administration, face increased risk of insider threats or compromised admin accounts being leveraged for lateral movement. The vulnerability could also impact compliance with security policies and regulations requiring strict access controls. Since exploitation requires existing administrative privileges, the threat is more significant in environments with multiple administrators or delegated permissions. The absence of known exploits reduces immediate risk, but the medium severity score and potential for significant damage warrant prompt mitigation.

Mitigation Recommendations

To mitigate CVE-2026-3121, organizations should first audit and review all realm-level administrative permissions in their Keycloak deployments, ensuring that 'manage-clients' permissions are not inadvertently granting broader 'manage-permissions' capabilities. Restrict the assignment of 'manage-clients' permission to trusted administrators only and consider implementing the principle of least privilege by minimizing administrative roles. Monitor administrative actions and enable detailed logging to detect unusual privilege escalations or configuration changes. Apply any official patches or updates from Red Hat promptly once available. If patches are not yet released, consider temporarily disabling realm-level administrative permissions or isolating administrative functions to reduce exposure. Employ multi-factor authentication (MFA) for all administrators to reduce the risk of compromised credentials being exploited. Regularly review Keycloak configuration and permission mappings to detect and correct misconfigurations. Additionally, conduct periodic security assessments and penetration testing focused on identity and access management components to identify similar privilege escalation risks.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
redhat
Date Reserved
2026-02-24T13:09:39.644Z
Cvss Version
3.1
State
PUBLISHED

Threat ID: 69c589333c064ed76fb16803

Added to database: 03/26/2026, 19:29:55 UTC

Last enriched: 04/03/2026, 03:21:03 UTC

Last updated: 07/31/2026, 19:22:58 UTC

Views: 240

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses