This advisory has been withdrawn because it is a duplicate of GHSA-27gp-8389-hm4w. This link is maintained to preserve external references.
A flaw was found in the Keycloak identity and access management system when Fine-Grained Admin Permissions (FGAPv2) are enabled. An administrative user with the manage-users role can escalate their privileges to realm-admin due to improper privilege enforcement. This vulnerability allows unauthorized elevation of access rights, compromising the intended separation of administrative duties and posing a security risk to the realm.
{
"cwe_ids": [
"CWE-269"
],
"github_reviewed_at": "2025-07-21T12:26:17Z",
"nvd_published_at": "2025-07-18T14:15:26Z",
"severity": "MODERATE",
"github_reviewed": true
}