CVE-2025-14778 Details
Description
A flaw was found in Keycloak. A significant Broken Access Control vulnerability exists in the UserManagedPermissionService (UMA Protection API). When updating or deleting a UMA policy associated with multiple resources, the authorization check only verifies the caller's ownership against the first resource in the policy's list. This allows a user (Owner A) who owns one resource (RA) to update a shared policy and modify authorization rules for other resources (e.g., RB) in that same policy, even if those other resources are owned by a different user (Owner B). This constitutes a horizontal privilege escalation.
A significant broken access control vulnerability has been identified in Keycloak's UserManagedPermissionService, part of the UMA Protection API. This vulnerability allows a user (Owner A) who owns one resource to update a shared policy and alter authorization rules for other resources in that policy, even if those resources are owned by a different user (Owner B). The issue arises because the authorization check only verifies ownership against the first resource in the policy's list, leading to horizontal privilege escalation.
Users can upgrade to the Red Hat build of Keycloak 26.2.13 or 26.4.9, both of which include the necessary fix. Instructions for downloading these versions are available on the Red Hat Customer Portal.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Feb 9, 2026CISA-ADP
Assessed Feb 9, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2026:2363 | [email protected] | AdvisoryBundleRemedyVendor |
| https://access.redhat.com/errata/RHSA-2026:2364 | [email protected] | AdvisoryBundleRemedyVendor |
| https://access.redhat.com/errata/RHSA-2026:2365 | [email protected] | AdvisoryBundleRemedyVendor |
| https://access.redhat.com/errata/RHSA-2026:2366 | [email protected] | AdvisoryBundleRemedyVendor |
| https://access.redhat.com/security/cve/CVE-2025-14778 | [email protected] | AdvisoryVendor |
| https://bugzilla.redhat.com/show_bug.cgi?id=2422600 | [email protected] | Issue TrackingTechnical DescriptionVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-266 | Incorrect Privilege Assignment | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Red Hat build of Keycloak | >= 26.2.0, < 26.2.13 (semver) >= 26.4.0, < 26.4.9 (semver) |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 10, 2026 | CVE Modified | [email protected] |
| Feb 9, 2026 | CVE Modified | [email protected] |
| Feb 9, 2026 | New CVE Received | [email protected] |
Volerion