Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-96448— Keycloak-services: keycloak-services: fgap v2 composite-blind role mapping allows privilege escalation

Quick assessment

Affected
Red Hat Red Hat Build of Keycloak
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在身份与访问管理解决方案 Keycloak 中,其细粒度管理员权限(Fine-Grained Admin Permissions,简称 FGAP v2)功能存在一处漏洞。当系统验证被委派的管理员是否有权将特定角色分配给用户时,由于该检查未深入查看复合角色(composite roles)所包含的其他权限,导致权限受限的管理员可以分配一个实质上包含完整管理控制权的角色。攻击者借此可获得对整个领域(realm)的完全管理访问权限。

CVSS 6.6 · Medium EPSS 0.24% · P13
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-96448

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Keycloak-services: keycloak-services: fgap v2 composite-blind role mapping allows privilege escalation
Source: CVE Program / CVE List V5
Vulnerability Description
A flaw was found in the Fine-Grained Admin Permissions (FGAP v2) feature of Keycloak, an identity and access management solution. The issue occurs when the system checks if a delegated administrator has permission to assign a specific role to a user. Because the check does not look inside composite roles to see what other permissions they contain, an administrator with limited rights can assign a role that secretly includes full administrative control. This allows the attacker to gain complete management access over the entire realm.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Red Hat Red Hat Build of Keycloak - cpe:/a:redhat:build_keycloak:
Red Hat Red Hat Build of Keycloak - cpe:/a:redhat:build_keycloak:
Red Hat Red Hat Single Sign-On 7 - cpe:/a:redhat:red_hat_single_sign_on:7

II. Public POCs for CVE-2026-96448

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-96448

请登录查看更多情报信息。

Other References for CVE-2026-96448 (2)

Same Patch Batch · Red Hat · 2026-09-25 · 3 CVEs total

CVE-2026-93834 8.8 HIGH Qemu-kvm: 9pfs: use-after-free race in tlcreate/twalk allows vm guest escape
CVE-2026-97846 6.8 MEDIUM Keycloak-services: keycloak-services: standard token exchange v2 bypasses mtls holder-of-k

IV. Related Vulnerabilities

V. Comments for CVE-2026-96448

No comments yet


Leave a comment