在身份与访问管理解决方案 Keycloak 中,其细粒度管理员权限(Fine-Grained Admin Permissions,简称 FGAP v2)功能存在一处漏洞。当系统验证被委派的管理员是否有权将特定角色分配给用户时,由于该检查未深入查看复合角色(composite roles)所包含的其他权限,导致权限受限的管理员可以分配一个实质上包含完整管理控制权的角色。攻击者借此可获得对整个领域(realm)的完全管理访问权限。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Build of Keycloak | - |
cpe:/a:redhat:build_keycloak:
|
|
| Red Hat | Red Hat Build of Keycloak | - |
cpe:/a:redhat:build_keycloak:
|
|
| Red Hat | Red Hat Single Sign-On 7 | - |
cpe:/a:redhat:red_hat_single_sign_on:7
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-93834 | 8.8 HIGH | Qemu-kvm: 9pfs: use-after-free race in tlcreate/twalk allows vm guest escape |
| CVE-2026-97846 | 6.8 MEDIUM | Keycloak-services: keycloak-services: standard token exchange v2 bypasses mtls holder-of-k |
No comments yet