Home

Description

A flaw was found in Keycloak. A limited administrator can exploit an improper access control vulnerability in the POST /admin/realms/{realm}/partialImport endpoint. This allows them to bypass Fine-Grained Admin Permissions (FGAP) and escalate their privileges to a full realm administrator by importing users with realm-admin role mappings.

PUBLISHED Reserved 2026-06-08 | Published 2026-06-08 | Updated 2026-06-08 | Assigner redhat




HIGH: 7.2CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Problem types

Incorrect Authorization

Product status

Default status
affected

Default status
affected

Default status
affected

Default status
affected

Default status
unknown

Timeline

2026-04-18:Reported to Red Hat.
2026-06-08:Made public.

Credits

Red Hat would like to thank Andrii Ilin (10Guards) for reporting this issue.

References

access.redhat.com/security/cve/CVE-2026-11577 vdb-entry

bugzilla.redhat.com/show_bug.cgi?id=2459993 (RHBZ#2459993) issue-tracking

github.com/keycloak/keycloak/issues/9387

cve.org (CVE-2026-11577)

nvd.nist.gov (CVE-2026-11577)

Download JSON