Description


A flaw was found in the ClientResource component of Keycloak's admin services when Fine-Grained Admin Permissions (FGAP) v2 is enabled. This issue allows a delegated administrator, who should only have limited control over specific clients, to attach or remove hidden client scopes that they are not authorized to see or manage. As a result, an attacker could inject unauthorized data or permissions into the security tokens issued to end-users, potentially tricking other applications into granting higher levels of access than intended.

Related CPE's


a

redhat

build_of_keycloak

2

Weaknesses



CWE-639

134c704f-9b21-4f2e-91b3-4a467353bcc0

Secondary

CWE-284

CVSS impact metrics


CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

5.4 · Medium

Information


Source identifier

[email protected]

Vulnerability status

Analyzed

Published

2026-07-03T16:16:55.650Z

3 months ago

Last modified

2026-08-11T15:06:15.343Z

1 month ago