Keycloak disclosed and patched a high-severity privilege escalation flaw, CVE-2026-9795, in its Fine-Grained Admin Permissions v2 (FGAPv2) feature after researchers reported that a delegated administrator could bypass missing authorization checks in the admin REST API and add arbitrary realm roles to a client’s scope mapping. That weakness allowed limited administrators to inject elevated roles such as realm-admin into tokens later issued to users authenticating through the affected client, creating a path to downstream privilege escalation in deployments running Keycloak 26.2.0 and later with FGAPv2 enabled.
The issue was later listed as fixed in Keycloak release 26.6.4, alongside several other security bugs including CVE-2026-9099, CVE-2026-9083, CVE-2026-9086, CVE-2026-9705, CVE-2026-9799, CVE-2026-9800, and CVE-2026-11800. Red Hat also shipped security updates for its Keycloak 26.4.11 images and operator on OpenShift, addressing a broad set of vulnerabilities across the Admin REST API, Account REST API, OIDC dynamic client registration, UMA authorization, token handling, redirect validation, and scope processing, with impacts ranging from information disclosure and SSRF to account takeover, policy bypass, and denial of service.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
By the 2026-07-09 releases page, Keycloak release 26.6.4 was documented as fixing CVE-2026-9795 along with CVE-2026-9099, CVE-2026-9083, CVE-2026-9086, CVE-2026-9705, CVE-2026-9799, CVE-2026-9800, and CVE-2026-11800. This marks the availability of an upstream patch for the disclosed FGAPv2 privilege escalation issue.
On 2026-05-27, ZeroPath published details of CVE-2026-9795, a high-severity privilege escalation flaw in Keycloak's Fine-Grained Admin Permissions v2 caused by a missing authorization check in the admin REST API. The write-up said affected deployments started with version 26.2.0 when FGAPv2 is enabled and noted that 26.6.2 reportedly did not yet contain a fix as of late May 2026.
Keycloak announced release 26.5.7 on 2026-04-02. The reference identifies this as a distinct product release event.
On 2026-04-02, Red Hat published security advisory RHSA-2026:6478 and released updated Red Hat build of Keycloak 26.4.11 images and operator packages for OpenShift. The advisory addressed multiple vulnerabilities across Keycloak components including access control, SSRF, privilege escalation, account takeover, replay, policy bypass, and denial of service issues.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourcezeropath.com
Open sourceaccess.redhat.com
Open sourcekeycloak.org
Open sourcedatatracker.ietf.org
Open sourcedatatracker.ietf.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.