ECHO-73ab-600d-62be

See a problem?
Import Source
https://advisory.echohq.com/osv/ECHO-73ab-600d-62be.json
JSON Data
https://api.osv.dev/v1/vulns/ECHO-73ab-600d-62be
Upstream
  • CVE-2026-3121
Withdrawn
2026-08-31T14:30:19Z
Published
2026-08-30T16:45:31Z
Modified
2026-08-31T15:15:02Z
Summary
Caught by Cursor Bugbot review on PR #19827: the real vulnerability (GHSA-7xf9-4jfc-wgm4) is specific to Fine-Grained Admin Permissions V2's RealmPermissionsV2 treating manage-clients as equivalent to managing the special "admin-permissions" client, which then grants realm-wide admin power. RealmPermissionsV2 and the admin-permissions client concept do not exist in 25.0.6 — its older RealmPermissions.canManageAuthorizationDefault() has no per-ResourceServer parameter at all (it's a single, undifferentiated realm-wide check), so there is no "is this the special admin-permissions client" distinction for a narrow, upstream-faithful fix to attach to. An earlier patch here unconditionally removed MANAGE_CLIENTS from that check to close the described escalation, but that changes intended authorization behavior for every regular client's authorization management, not just a vulnerable path (upstream's real fix leaves the MANAGE_CLIENTS grant intact for non-admin-permissions clients) — reverted.
Details
References

Affected packages

Echo / keycloak-25

Package

Name
keycloak-25
Purl
pkg:deb/echo/keycloak-25

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
25.0.6+e2

Database specific

source
"https://advisory.echohq.com/osv/ECHO-73ab-600d-62be.json"

Echo:Maven / org.keycloak:keycloak-services

Package

Name
org.keycloak:keycloak-services
Purl
pkg:maven/org.keycloak/keycloak-services

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Database specific

source
"https://advisory.echohq.com/osv/ECHO-73ab-600d-62be.json"