CVE-2026-96448 Overview
CVE-2026-96448 is a privilege escalation flaw in the Fine-Grained Admin Permissions (FGAP v2) feature of Keycloak, an open-source identity and access management (IAM) solution. The authorization check that validates whether a delegated administrator may assign a role to a user does not recursively evaluate composite roles. A delegated administrator with limited rights can assign a role whose nested composites include full administrative privileges. The result is complete management control over the entire realm. The weakness is tracked under CWE-285: Improper Authorization.
Critical Impact
An authenticated delegated administrator can escalate to full realm administrator by assigning a composite role that transitively grants administrative permissions.
Affected Products
- Keycloak (Fine-Grained Admin Permissions v2 feature)
- Red Hat build of Keycloak
- Red Hat Single Sign-On distributions bundling the affected FGAP v2 implementation
Discovery Timeline
- 2026-09-25 - CVE-2026-96448 published to the National Vulnerability Database (NVD)
- 2026-09-26 - Last updated in the NVD database
Technical Details for CVE-2026-96448
Vulnerability Analysis
Keycloak's FGAP v2 feature lets realm owners delegate narrow administrative tasks, such as assigning specific roles, to lower-privileged administrators. When a delegated admin attempts to assign a role, Keycloak checks whether the caller has the map-role permission on that specific role. The check stops at the top-level role identifier and does not descend into composite role membership.
Composite roles in Keycloak can aggregate any number of other roles, including client roles such as realm-management:realm-admin. Because the authorization decision ignores the composite expansion, a role that appears benign to the permission model can transitively grant realm-admin rights. Once assigned, the target user inherits every nested permission.
Exploitation requires an authenticated attacker with existing FGAP delegation rights and some knowledge of composite role structures. The attack complexity reflects the need to identify a composite role that chains into administrative permissions, but the resulting impact is full control of the realm's confidentiality, integrity, and availability.
Root Cause
The root cause is incomplete authorization logic in the role-assignment permission evaluator. The evaluator validates map-role on the immediate role object without walking the composite membership graph. This is a design-level [CWE-285] Improper Authorization defect rather than a memory or input-validation bug.
Attack Vector
The attack vector is network-based through Keycloak's Admin REST API or Admin Console. An attacker authenticates as a delegated administrator, enumerates assignable roles via /admin/realms/{realm}/roles, and selects a composite role that contains administrative sub-roles. The attacker then issues a role mapping request against a user they control, inheriting administrative privileges on next login or token refresh.
See the Red Hat CVE-2026-96448 advisory and Red Hat Bug Report #2539291 for additional technical context. No verified public proof-of-concept code is available at the time of writing.
Detection Methods for CVE-2026-96448
Indicators of Compromise
- Role mapping events in Keycloak admin audit logs where the assigned role is a composite that transitively includes realm-management client roles such as realm-admin, manage-users, or manage-realm.
- Unexpected membership changes for sensitive groups or roles performed by non-super-admin accounts.
- Token issuance for users showing a sudden expansion of resource_access.realm-management.roles claims following a role assignment.
Detection Strategies
- Enable Keycloak Event Listener SPI with admin-events enabled and forward events to a SIEM for correlation.
- Build detections that expand composite roles at ingest time and flag any assignment where the effective role set includes administrative permissions but the actor is not a top-level realm admin.
- Alert on API calls to POST /admin/realms/{realm}/users/{id}/role-mappings/* from accounts that normally do not perform role mapping.
Monitoring Recommendations
- Baseline which delegated administrators assign which roles, and alert on deviations.
- Monitor for new users or service accounts that acquire administrative client roles outside of change-management windows.
- Review FGAP v2 permission policies monthly to confirm no composite role granting administrative sub-roles is assignable by delegated admins.
How to Mitigate CVE-2026-96448
Immediate Actions Required
- Apply the Keycloak and Red Hat build of Keycloak updates referenced in the Red Hat CVE-2026-96448 advisory as soon as they are available.
- Audit all FGAP v2 permission policies and remove any grant that allows delegated administrators to assign composite roles containing administrative sub-roles.
- Review audit logs for the last 90 days for unexpected administrative role assignments and revoke them where unauthorized.
Patch Information
Refer to the Red Hat CVE-2026-96448 advisory and Red Hat Bugzilla #2539291 for fixed version numbers and errata affecting Red Hat build of Keycloak and Red Hat Single Sign-On. Upstream Keycloak releases that address the composite expansion check should be tracked through the Keycloak project release notes.
Workarounds
- Avoid delegating map-role permissions on composite roles; grant delegation only on explicit atomic roles.
- Restructure sensitive roles so that administrative permissions are never nested inside composites that could be assigned by delegated administrators.
- Where feasible, disable FGAP v2 for realms that do not require delegated administration and fall back to full realm admin assignment under change control.
# Example: list composite roles in a realm to identify assignable administrative paths
kcadm.sh get roles -r myrealm --fields id,name,composite \
| jq '.[] | select(.composite==true) | .name' \
| while read role; do
echo "Composite: $role"
kcadm.sh get "roles/$role/composites" -r myrealm --fields name,containerId
done
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.