PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-96448 Red Hat CVE debrief

A flaw in Keycloak's Fine-Grained Admin Permissions (FGAP v2) feature allows an administrator with limited rights to assign a role that secretly includes full administrative control, potentially leading to complete management access over the entire realm. This issue arises from the system's failure to properly check composite roles, enabling an attacker to gain unauthorized access. Keycloak administrators should assess their exposure and verify role assignments to prevent such unauthorized access.

Vendor
Red Hat
Product
Red Hat Build of Keycloak
CVSS
MEDIUM 6.6
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-25
Original CVE updated
2026-09-25
Advisory published
2026-09-25
Advisory updated
2026-09-25

Who should care

Keycloak administrators and security teams should assess exposure and verify role assignments to prevent unauthorized access. They should prioritize verifying and restricting role assignments, especially for administrators with limited rights, and monitor for suspicious activity related to role assignments.

Why it matters

CVE-2026-96448 allows an administrator with limited rights to assign a role that secretly includes full administrative control, potentially leading to complete management access over the entire realm. Defenders should prioritize verifying and restricting role assignments, especially for administrators with limited rights, and monitor for suspicious activity. The CVE record and NVD entry provide details on the vulnerability, but additional information on affected versions and remediation is needed.

  • Potential unauthorized role assignment by administrators with limited rights
  • Possible complete management access over the entire realm
  • Need for verification and restriction of role assignments
  • Importance of monitoring for suspicious activity

Technical summary

The Fine-Grained Admin Permissions (FGAP v2) feature in Keycloak does not properly check composite roles, allowing an administrator with limited rights to assign a role that includes full administrative control. This vulnerability enables an attacker to gain complete management access over the entire realm, highlighting the need for verifying and restricting role assignments, especially for administrators with limited rights, and monitoring for suspicious activity related to role assignments. Keycloak administrators and security teams should assess exposure and verify role assignments to prevent unauthorized access.

Defensive priority

Defenders should prioritize verifying and restricting role assignments, especially for administrators with limited rights, and monitor for suspicious activity.

Recommended defensive actions

  • Verify and restrict role assignments for administrators with limited rights
  • Monitor for suspicious activity related to role assignments
  • Review and update Keycloak configurations to prevent exploitation
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, but additional information on affected versions and remediation is needed. The Fine-Grained Admin Permissions (FGAP v2) feature in Keycloak does not properly check composite roles, allowing an administrator with limited rights to assign a role that includes full administrative control. Defenders should verify and restrict role assignments, especially for administrators with limited rights, and monitor for suspicious activity related to role assignments.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-96448 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-96448

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-96448 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-96448

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.