Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-94000— Keycloak-services: keycloak-services: delegated admin with manage-users can escalate to realm-admin via group membership

Quick assessment

Affected
Red Hat Red Hat Build of Keycloak
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Keycloak(一种开源的身份和访问管理解决方案)的 Admin REST API 中发现存在一个漏洞。该问题出现在群组成员管理端点中,系统在允许将用户添加到某个组之前,未检查该组是否授予了管理员权限。这可能导致拥有受限权限的委托管理员将自己添加到具有更高权限的组中,从而可能获得对整个领域(Realm)的完全控制权。

CVSS 6.6 · Medium

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-94000

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Keycloak-services: keycloak-services: delegated admin with manage-users can escalate to realm-admin via group membership
Source: CVE Program / CVE List V5
Vulnerability Description
A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution. The issue occurs in the group-membership endpoints where the system fails to check if a group grants administrative privileges before allowing a user to be added. This allows a delegated administrator with limited permissions to add themselves to a high-privilege group, potentially gaining full control over the entire realm.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制缺失
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Red Hat Red Hat Build of Keycloak - cpe:/a:redhat:build_keycloak:
Red Hat Red Hat Build of Keycloak - cpe:/a:redhat:build_keycloak:
Red Hat Red Hat Build of Keycloak - cpe:/a:redhat:build_keycloak:
Red Hat Red Hat Single Sign-On 7 - cpe:/a:redhat:red_hat_single_sign_on:7

II. Public POCs for CVE-2026-94000

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-94000

登录查看更多情报信息。

Vendor Advisories for CVE-2026-94000 (1)

Other References for CVE-2026-94000 (1)

Same Patch Batch · Red Hat · 2026-09-19 · 3 CVEs total

CVE-2026-94001 6.5 MEDIUM Keycloak-services: keycloak-services: admin credential delete bypasses denied reset-passwo
CVE-2026-93999 4.2 MEDIUM Keycloak-services: keycloak-services: token refresh continues issuing tokens for disabled

IV. Related Vulnerabilities

V. Comments for CVE-2026-94000

No comments yet


Leave a comment