CVE-2026-3121 identifies a privilege escalation vulnerability in Keycloak, where an administrator with 'manage-clients' permission can effectively gain 'manage-permissions' capabilities when realm-level admin permissions are enabled. This allows the attacker to escalate privileges and gain control over roles, users, and other administrative functions within the realm. Rated 6.5 MEDIUM, this vulnerability has a network attack vector and low attack complexity, but requires high privileges for exploitation, leading to high impact on confidentiality and integrity. Currently, there is no known active exploitation or public exploit code available, and community discussion is minimal since its recent publication.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:redhat:build_of_keycloak:-:*:*:*:-:*:*:* | ||
8.0.0CPE matchmatch criteria | cpe:2.3:a:redhat:jboss_enterprise_application_platform:8.0.0:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:redhat:jboss_enterprise_application_platform_expansion_pack:-:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:a:redhat:single_sign-on:7.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.