CVE-2026-17526: Keycloak-services: keycloak-services: privilege escalation via impersonation role allows takeover of realm administrator accounts
A flaw was found in Keycloak. A user holding only the impersonation realm-management client role can impersonate any enabled, non-service-account user in the realm, including full realm administrators. The impersonation endpoint restricts service accounts as targets but performs no privilege-level check on the target user. After impersonating an administrator, the attacker obtains a valid SSO session and can exchange it for a fully signed access token via a standard OIDC authorization-code flow, gaining complete administrative control over the realm (read/write all users, clients, roles, password resets). The impersonation role is designed as a lesser delegation for support staff, and this flaw defeats that separation.
Other sources
Keycloak is an open-source identity and access management solution. A vulnerability was discovered where a user with the impersonation role can impersonate a realm administrator. This allows the attacker to gain full administrative control over the realm, including the ability to manage users, clients, and roles.
— MITRE
Affected Software
Event History
Frequently Asked Questions
Which accounts are at risk of being taken over?
Any enabled, non-service-account user in the affected realm can be impersonated, including users with full realm-administrator privileges. Service accounts are restricted as impersonation targets.
What access does an attacker need before exploitation?
The attacker must already hold the impersonation realm-management client role. No interaction from the target user is required.
How does impersonation become full administrative access?
After impersonating an administrator, the attacker receives a valid SSO session and can use a standard OIDC authorization-code flow to obtain a signed access token. That token provides complete administrative control over the realm, including management of users, clients, roles, and password resets.