CVE-2026-4628 describes an improper access control vulnerability in Keycloak’s User-Managed Access (UMA) resource_set endpoint. This flaw allows authenticated attackers to bypass the allowRemoteResourceManagement=false restriction due to incomplete access control checks on PUT operations, leading to unauthorized modification of protected resources and impacting data integrity. Rated Medium with a CVSS score of 4.3, this vulnerability has a low attack complexity and requires low privileges for a network-based attacker. There is currently no evidence of active exploitation, nor are public exploit codes or significant community discussion available for this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:redhat:build_of_keycloak:-:*:*:*:-:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Keycloak has Improper Access Control that allows attackers with valid credentials to bypass the allowRemoteResourceManagement=false
Mar 23, 2026keycloak: org.keycloak.authorization: Keycloak: Unauthorized resource modification due to improper access control
Mar 23, 2026