Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-17526— Keycloak-services: keycloak-services: privilege escalation via impersonation role allows takeover of realm administrator accounts

Quick assessment

Affected
Red Hat Red Hat build of Keycloak 26.4
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Keycloak 是一款开源的身份与访问管理解决方案。研究人员发现了一个漏洞:拥有“模拟(impersonation)”角色的用户可以模拟(impersonate)领域(realm)管理员。这使得攻击者能够获取对领域(realm)的完全管理权限,包括管理用户、客户端和角色的能力。

CVSS 7.2 · High

Possible ATT&CK Techniques 1 AI

T1098.004 · SSH Authorized Keys
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-17526

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Keycloak-services: keycloak-services: privilege escalation via impersonation role allows takeover of realm administrator accounts
Source: CVE Program / CVE List V5
Vulnerability Description
Keycloak is an open-source identity and access management solution. A vulnerability was discovered where a user with the impersonation role can impersonate a realm administrator. This allows the attacker to gain full administrative control over the realm, including the ability to manage users, clients, and roles.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制缺失
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Red Hat Red Hat build of Keycloak 26.4 26.4-26 ~ * cpe:/a:redhat:build_keycloak:26.4::el9
Red Hat Red Hat build of Keycloak 26.4 26.4-26 ~ * cpe:/a:redhat:build_keycloak:26.4::el9
Red Hat Red Hat build of Keycloak 26.4 26.4.16-2 ~ * cpe:/a:redhat:build_keycloak:26.4::el9
Red Hat Red Hat build of Keycloak 26.4.16 - cpe:/a:redhat:build_keycloak:26.4::el9
Red Hat Red Hat build of Keycloak 26.4.16 - cpe:/a:redhat:build_keycloak:26.4::el9
Red Hat Red Hat build of Keycloak 26.6 26.6-20 ~ * cpe:/a:redhat:build_keycloak:26.6::el9
Red Hat Red Hat build of Keycloak 26.6 26.6.7-3 ~ * cpe:/a:redhat:build_keycloak:26.6::el9
Red Hat Red Hat build of Keycloak 26.6 26.6-20 ~ * cpe:/a:redhat:build_keycloak:26.6::el9
Red Hat Red Hat build of Keycloak 26.6.7 - cpe:/a:redhat:build_keycloak:26.6::el9
Red Hat Red Hat build of Keycloak 26.6.7 - cpe:/a:redhat:build_keycloak:26.6::el9
Red Hat Red Hat build of Keycloak 26.6.7 - cpe:/a:redhat:build_keycloak:26.6::el9
Red Hat Red Hat Data Grid 8 - cpe:/a:redhat:jboss_data_grid:8
Red Hat Red Hat JBoss Enterprise Application Platform Expansion Pack - cpe:/a:redhat:jbosseapxp
Red Hat Red Hat Single Sign-On 7 - cpe:/a:redhat:red_hat_single_sign_on:7

II. Public POCs for CVE-2026-17526

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-17526

登录查看更多情报信息。

Vendor Advisories for CVE-2026-17526 (1)

Other References for CVE-2026-17526 (5)

Same Patch Batch · Red Hat · 2026-09-16 · 9 CVEs total

CVE-2026-74909 8.1 HIGH Keycloak-services: keycloak-services: incomplete fix for cve-2026-15573 allows policy enfo
CVE-2026-79651 7.5 HIGH Keycloak-services: keycloak-services: unauthenticated dos via unbounded locale caching
CVE-2026-18212 7.5 HIGH Keycloak-services: keycloak-services: saml redirect deflate helpers leak native zlib state
CVE-2026-42784 7.4 HIGH Sequoia-openpgp: sequoia-openpgp: cryptographic integrity compromise via key flag confusio
CVE-2026-92615 6.6 MEDIUM Flightctl: flightctl: package-global go-git https transport mutated per-repo -- cross-tena
CVE-2026-92358 6.4 MEDIUM Keycloak-services: keycloak-services: residual cross-browser account-link proof allows sil
CVE-2026-92091 5.9 MEDIUM Jwcrypto: jwcrypto: denial of service via o(n^2) duplicate check on unbounded jwk key_ops
CVE-2026-19607 5.3 MEDIUM Keycloak-services: keycloak-services: broker-originated username collision causes account

IV. Related Vulnerabilities

V. Comments for CVE-2026-17526

No comments yet


Leave a comment