Description
A flaw was found in Keycloak. A limited administrator can exploit an improper access control vulnerability in the POST /admin/realms/{realm}/partialImport endpoint. This allows them to bypass Fine-Grained Admin Permissions (FGAP) and escalate their privileges to a full realm administrator by importing users with realm-admin role mappings.
Problem types
Product status
Timeline
| 2026-04-18: | Reported to Red Hat. |
| 2026-06-08: | Made public. |
Credits
Red Hat would like to thank Andrii Ilin (10Guards) for reporting this issue.
References
access.redhat.com/security/cve/CVE-2026-11577
bugzilla.redhat.com/show_bug.cgi?id=2459993 (RHBZ#2459993)
github.com/keycloak/keycloak/issues/9387