๐Ÿ” CVE Alert

CVE-2025-7784

MEDIUM 6.5

Org.keycloak/keycloak-services: privilege escalation in keycloak admin console (fgapv2 enabled)

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th

A flaw was found in the Keycloak identity and access management system when Fine-Grained Admin Permissions(FGAPv2) are enabled. An administrative user with the manage-users role can escalate their privileges to realm-admin due to improper privilege enforcement. This vulnerability allows unauthorized elevation of access rights, compromising the intended separation of administrative duties and posing a security risk to the realm.

CWE CWE-269
Published Jul 18, 2025
Last Updated Nov 7, 2025
Stay Ahead of the Next One

Get instant alerts for

Be the first to know when new medium vulnerabilities are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None

Affected Versions

Red Hat / Red Hat build of Keycloak 26
All versions affected
Red Hat / Red Hat build of Keycloak 26.2
All versions affected
Red Hat / Red Hat build of Keycloak 26.2
All versions affected
Red Hat / Red Hat build of Keycloak 26.2
All versions affected
Red Hat / Red Hat JBoss Enterprise Application Platform 8
All versions affected
Red Hat / Red Hat JBoss Enterprise Application Platform Expansion Pack
All versions affected
Red Hat / Red Hat Single Sign-On 7
All versions affected

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
access.redhat.com: https://access.redhat.com/errata/RHSA-2025:12015 access.redhat.com: https://access.redhat.com/errata/RHSA-2025:12016 access.redhat.com: https://access.redhat.com/security/cve/CVE-2025-7784 bugzilla.redhat.com: https://bugzilla.redhat.com/show_bug.cgi?id=2381861

Credits

Red Hat would like to thank Patrick Kutz for reporting this issue.