This advisory has been withdrawn because it is a duplicate of GHSA-27gp-8389-hm4w. This link is maintained to preserve external references.
A flaw was found in the Keycloak identity and access management system when Fine-Grained Admin Permissions (FGAPv2) are enabled. An administrative user with the manage-users role can escalate their privileges to realm-admin due to improper privilege enforcement. This vulnerability allows unauthorized elevation of access rights, compromising the intended separation of administrative duties and posing a security risk to the realm.
{ "severity": "MODERATE", "github_reviewed_at": "2025-07-21T12:26:17Z", "nvd_published_at": "2025-07-18T14:15:26Z", "cwe_ids": [ "CWE-269" ], "github_reviewed": true }