CVE-2026-3121
Last modified
CVE-2026-3121 is a high-severity vulnerability rated 7.2/10 on the CVSS scale. A flaw was found in Keycloak. An administrator with `manage-clients` permission can exploit a misconfiguration where this permission is equivalent to `manage-permissions`. EPSS estimates a 0.47% chance of exploitation in the next 30 days.
Description
A flaw was found in Keycloak. An administrator with `manage-clients` permission can exploit a misconfiguration where this permission is equivalent to `manage-permissions`. This allows the administrator to escalate privileges and gain control over roles, users, or other administrative functions within the realm. This privilege escalation can occur when admin permissions are enabled at the realm level.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Build Of Keycloak | All versions |
| Redhat | Jboss Enterprise Application Platform | 8.0.0 |
| Redhat | Jboss Enterprise Application Platform Expansion Pack | All versions |
| Redhat | Single Sign-On | 7.0 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2026-3121?
How severe is CVE-2026-3121?
How do I fix CVE-2026-3121?
Are you affected by CVE-2026-3121?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
