CVE-2020-27826: Medium severity red hat keycloak vulnerability
A flaw was found in Keycloak before version 12.0.0 where it is possible to update the user's metadata attributes using Account REST API. This flaw allows an attacker to change its own NameID attribute to impersonate the admin user for any particular application.
Other sources
A flaw was found in keycloak where it is possible to update the user's metadata attributes using Account REST API. It is now possible for any evil user to change its own NameID attribute to impersonate the admin user for any particular application.
— Red Hat
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2020-27826.
What is the severity of CVE-2020-27826?
The severity of CVE-2020-27826 is medium.
How does CVE-2020-27826 impact Keycloak?
CVE-2020-27826 allows an attacker to change its own NameID attribute to impersonate the admin user for any particular application in Keycloak.
Which versions of Keycloak are affected by CVE-2020-27826?
Keycloak versions before 12.0.0 are affected by CVE-2020-27826.
How can I fix CVE-2020-27826 in Keycloak?
To fix CVE-2020-27826 in Keycloak, you should update to version 12.0.0 or later.