CVE-2026-94000 Overview
CVE-2026-94000 is a missing authorization flaw [CWE-862] in the Admin REST API of Keycloak, an open-source identity and access management platform. The group-membership endpoints fail to verify whether a target group grants administrative privileges before allowing membership changes. A delegated administrator with limited permissions can add themselves to a high-privilege group and gain full control over the realm. Successful exploitation results in privilege escalation across the identity provider, compromising every application and service that trusts the affected realm.
Critical Impact
A delegated administrator can escalate to full realm control by adding their own account to a privileged group, undermining the trust boundary of every downstream application.
Affected Products
- Keycloak (open-source identity and access management)
- Red Hat Build of Keycloak
- Red Hat Single Sign-On distributions incorporating the vulnerable Admin REST API
Discovery Timeline
- 2026-09-19 - CVE-2026-94000 published to the National Vulnerability Database
- 2026-09-22 - Last updated in NVD database
Technical Details for CVE-2026-94000
Vulnerability Analysis
The flaw resides in the Keycloak Admin REST API endpoints that manage group membership. When a caller requests that a user be added to a group, the server verifies that the caller holds the manage-users or equivalent group-management permission. However, it does not evaluate whether the destination group itself confers administrative roles on its members.
This oversight breaks Keycloak's delegated administration model. Realms commonly grant scoped administrators the ability to manage a subset of users, expecting that scope to constrain the blast radius. Because the group's role composition is not checked at the authorization boundary, a scoped administrator can promote arbitrary users into a group mapped to realm-admin or similar high-privilege roles.
The attack requires an authenticated account with existing delegated permissions, which is why the CVSS attack complexity and privileges required are elevated. Impact on confidentiality, integrity, and availability remain high because realm-admin authority permits changes to clients, identity providers, and user credentials.
Root Cause
The root cause is a missing authorization check [CWE-862] at the group-membership endpoint. The endpoint validates the caller's permission to modify group members but omits a secondary check confirming that the caller is also authorized to grant every role composed into the target group. This is a classic broken access control pattern where authorization is enforced on the action but not on the resulting effective permissions.
Attack Vector
Exploitation proceeds over the network against the Keycloak Admin REST API. An attacker authenticates using a delegated administrator account, enumerates groups within their reachable scope, and issues a PUT request to the group-membership endpoint (/admin/realms/{realm}/users/{userId}/groups/{groupId}) targeting a group that carries the realm-admin composite role. Once the request succeeds, the attacker's token is refreshed with the new group memberships and inherits realm-wide administrative authority.
No verified proof-of-concept code has been released. Refer to the Red Hat CVE-2026-94000 Advisory and Red Hat Bug Report #2537168 for vendor technical details.
Detection Methods for CVE-2026-94000
Indicators of Compromise
- Unexpected PUT or POST requests to /admin/realms/{realm}/users/{userId}/groups/{groupId} originating from accounts that do not routinely modify group membership.
- Keycloak admin events of type GROUP_MEMBERSHIP where the target group holds composite roles such as realm-admin, manage-realm, or manage-users.
- Newly issued access tokens containing elevated role claims for principals whose baseline entitlements do not include those roles.
- Login events for delegated administrator accounts followed shortly by administrative API activity outside their normal scope.
Detection Strategies
- Enable Keycloak admin event logging and forward GROUP_MEMBERSHIP events to a SIEM for correlation with the caller identity and target group composition.
- Baseline which service accounts and administrators legitimately modify group membership, then alert on deviations.
- Compare the composite roles of the destination group against the caller's own roles and flag any operation where the caller assigns roles they do not themselves hold.
Monitoring Recommendations
- Continuously audit the membership of groups mapped to realm-admin, create-realm, manage-clients, and manage-identity-providers.
- Monitor for token refresh operations that yield expanded role claims within short windows after a group-membership change.
- Alert on any Admin REST API call from IP ranges or user agents that have not previously interacted with administrative endpoints.
How to Mitigate CVE-2026-94000
Immediate Actions Required
- Apply the Keycloak security update referenced in the Red Hat CVE-2026-94000 Advisory as soon as a fixed build is available for your distribution.
- Review all accounts with delegated manage-users or manage-members permissions and confirm they are still required.
- Audit membership of every high-privilege group and remove any account added without a documented change request.
- Rotate credentials and revoke active sessions for any account suspected of exploiting the flaw.
Patch Information
Refer to the Red Hat CVE-2026-94000 Advisory and Red Hat Bug Report #2537168 for fixed versions of Keycloak and Red Hat Build of Keycloak. Upstream Keycloak releases incorporating the authorization check should be adopted for community deployments.
Workarounds
- Restrict the manage-users and group-management roles to a minimal set of trusted administrators until the patch is deployed.
- Remove composite administrative roles from groups that must remain writable by delegated administrators; assign those roles directly to individual accounts instead.
- Place the Keycloak Admin REST API behind a network policy or reverse proxy that limits access to a defined administrative subnet.
- Enable strict admin event auditing and require change tickets for any modification to privileged group membership.
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.