REDHAT-BUG-2539965: Medium severity Red Hat Keycloak vulnerability

Published Sep 24, 2026
·
Updated

A Missing Authorization flaw was found in the org.keycloak.services.resources.admin package of Keycloak. The Admin REST API endpoint for updating user information (PUT /admin/realms/{realm}/users/{id}) enforces generic user management permissions (requireManage) but fails to validate fine-grained reset-password authorization (requireResetPassword). In environments where Fine-Grained Admin Permissions (FGAP) are enabled, a delegated administrator who has been granted manage permissions but is explicitly denied reset-password authority can include a credentials object in the user update payload. Because the specific permission check is missing in this code path, the password update is processed successfully. Successful exploitation allows a restricted administrator to: Set a new password for any managed user.

Gain full unauthorized access to victim accounts (account takeover).

Lock legitimate users out of their accounts.

Affected Software

1 affected component
Red Hat Keycloak

Event History

Sep 24, 2026
Data Sourced
via Red Hat·05:39 AM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

Who can exploit this issue?

An authenticated delegated administrator in an environment with Fine-Grained Admin Permissions enabled can exploit it if they have generic user-management permission for a user but are explicitly denied reset-password permission.

2

Does exploitation require access to the Admin REST API?

Yes. The affected operation is the user update endpoint, PUT /admin/realms/{realm}/users/{id}, and the attacker must be able to submit an update payload containing a credentials object.

3

What is the impact of a successful exploit?

The restricted administrator can set a new password for a managed user, take over that account, and potentially lock the legitimate user out.

4

How can administrators identify potentially affected activity?

Review use of the user update endpoint for payloads containing a credentials object, particularly actions performed by delegated administrators who have manage permission but lack reset-password authority.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203