PT-2025-30043 · Red Hat · Keycloak

Patrick Kutz

·

Published

2025-07-18

·

Updated

2026-05-06

·

CVE-2025-7784

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Keycloak (affected versions not specified)
Description A flaw exists in Keycloak when Fine-Grained Admin Permissions (FGAPv2) are enabled. An administrative user possessing the manage-users role can escalate privileges to realm-admin due to improper privilege enforcement. This allows unauthorized elevation of access rights, compromising the intended separation of administrative duties.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Improper Privilege Management

Weakness Enumeration

Related Identifiers

CVE-2025-7784
GHSA-27GP-8389-HM4W
GHSA-83J7-MHW9-388W

Affected Products

Keycloak