CVE-2026-9099 Details
Description
A flaw was found in Keycloak. A missing authorization check in the GroupResource.addChild() endpoint within the Admin REST API allows an authenticated user with limited administrative privileges to reparent any existing group. When Fine-Grained Admin Permissions v2 (FGAPv2) is enabled, an attacker with management rights over a single low-privilege group can reparent a highly privileged group (such as one possessing the realm-admin role) under their managed group. Because group permissions follow a hierarchical structure, this action unauthorizedly grants the attacker management and password-reset capabilities over the members of the targeted privileged group. An attacker can exploit this to reset an administrator's password, compromise the account, and achieve a full realm takeover, leading to a complete compromise of confidentiality, integrity, and availability.
A vulnerability exists in Keycloak due to a missing authorization check in the GroupResource.addChild() endpoint of the Admin REST API. This flaw enables an authenticated user with limited administrative rights to reparent any existing group. When Fine-Grained Admin Permissions v2 (FGAPv2) is activated, an attacker managing a low-privilege group can move a high-privilege group, such as one with the realm-admin role, under their control. This unauthorized action grants the attacker management and password-reset rights over the members of the privileged group, potentially allowing them to reset an administrator's password, compromise the account, and take full control of the realm.
To address this vulnerability, restrict network access to the Keycloak Admin REST API to trusted networks or localhost. This will prevent unauthorized access to the API endpoints that could be exploited. Consult network security documentation for specific firewall or access control configurations. Note that this may affect remote administration capabilities.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 25, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-639 | Authorization Bypass Through User-Controlled Key | redhat-SADP |
| CWE-639 | Authorization Bypass Through User-Controlled Key | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| redhat build of keycloak | >= 26.4, < 26.4.13 >= 26.6, < 26.6.4 |
CPE
Remediation
| |
Change History
8 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 15, 2026 | CVE Modified | redhat-SADP |
| Jul 1, 2026 | Initial Analysis | [email protected] |
| Jun 30, 2026 | CVE Modified | redhat-SADP |
| Jun 26, 2026 | CVE Modified | [email protected] |
| Jun 25, 2026 | CVE Modified | [email protected] |
| Jun 25, 2026 | CVE Modified | CISA-ADP |
| Jun 25, 2026 | CVE Modified | [email protected] |
| Jun 25, 2026 | New CVE Received | [email protected] |