A flaw was found in the Keycloak identity and access management system when Fine-Grained Admin Permissions (FGAPv2) are enabled. An administrative user with the manage-users role can escalate their privileges to realm-admin due to improper privilege enforcement. This vulnerability allows unauthorized elevation of access rights, compromising the intended separation of administrative duties and posing a security risk to the realm.
{ "github_reviewed": true, "github_reviewed_at": "2025-07-21T12:26:17Z", "cwe_ids": [ "CWE-269" ], "severity": "MODERATE", "nvd_published_at": "2025-07-18T14:15:26Z" }