Description
A flaw was found in Keycloak. An improper Access Control vulnerability in Keycloak’s User-Managed Access (UMA) resource_set endpoint allows attackers with valid credentials to bypass the allowRemoteResourceManagement=false restriction. This occurs due to incomplete enforcement of access control checks on PUT operations to the resource_set endpoint. This issue enables unauthorized modification of protected resources, impacting data integrity.
Problem types
Product status
Timeline
| 2026-03-23: | Reported to Red Hat. |
| 2026-03-23: | Made public. |
Credits
Red Hat would like to thank Evan Hendra for reporting this issue.
References
access.redhat.com/security/cve/CVE-2026-4628
bugzilla.redhat.com/show_bug.cgi?id=2450240 (RHBZ#2450240)