CVE-2026-97177 Overview
CVE-2026-97177 is a missing authorization flaw [CWE-862] in the Keycloak Admin REST API user update mechanism. When Fine-Grained Admin Permissions are enabled, Keycloak does not verify specific password-reset authorizations during a general user profile update. A delegated administrator who is restricted from resetting passwords can modify a target user's credentials through the profile update endpoint and take over the account. The flaw affects identity and access management deployments that rely on Keycloak's delegated administration model to enforce separation of duties between help-desk, support, and security personas.
Critical Impact
A delegated administrator can bypass password-reset restrictions, change arbitrary user credentials, and take over accounts, including those with higher privileges.
Affected Products
- Keycloak (Red Hat build of Keycloak)
- Red Hat Single Sign-On based on Keycloak
- Any Keycloak deployment using Fine-Grained Admin Permissions
Discovery Timeline
- 2026-09-24 - CVE CVE-2026-97177 published to NVD
- 2026-09-24 - Last updated in NVD database
Technical Details for CVE-2026-97177
Vulnerability Analysis
The flaw resides in the Keycloak Admin REST API code path that handles user profile updates. Fine-Grained Admin Permissions let administrators grant scoped rights such as manage-users without granting the dedicated reset-password right. The user update endpoint evaluates only the general update authorization and does not re-check for the credential-specific authorization when the submitted payload contains credential fields. Any administrator holding the broader update right can therefore write to the credentials collection and set a new password. The result is a privilege boundary violation that undermines separation of duties within the identity platform.
Root Cause
The root cause is missing authorization enforcement [CWE-862] on a sensitive sub-resource of the user object. The server performs a single coarse permission check at the entry of the update handler and treats all mutable fields uniformly. Credential changes should trigger an additional policy evaluation that validates the manage-credentials or password-reset scope defined by Fine-Grained Admin Permissions.
Attack Vector
Exploitation requires network access to the Keycloak Admin REST API and valid credentials for a delegated administrator account with user management rights but without password-reset rights. The attacker issues an authenticated PUT request to the user resource and includes a credentials object in the JSON body. Keycloak accepts the update and overwrites the target user's password, enabling account takeover on the next login attempt.
No verified public exploit code is available. For technical details, review the Red Hat CVE-2026-97177 advisory and Red Hat Bug #2539965.
Detection Methods for CVE-2026-97177
Indicators of Compromise
- Admin REST API PUT /admin/realms/{realm}/users/{id} requests containing a credentials array originating from accounts that lack the password-reset scope.
- Unexpected UPDATE_PASSWORD or UPDATE_CREDENTIAL events in the Keycloak admin event log tied to delegated administrator principals.
- Successful user logins immediately following an administrative profile update performed by a non-privileged admin.
Detection Strategies
- Enable Keycloak admin event logging with includeRepresentation=true and alert on update events whose representation contains credential fields.
- Correlate the acting administrator's role set with the fields modified in each user update; flag any credential mutation performed by an admin without the password-reset permission.
- Baseline normal delegated-admin behavior and alert on deviations such as credential writes outside maintenance windows.
Monitoring Recommendations
- Forward Keycloak admin and user events to a centralized SIEM for retention and correlation with downstream authentication activity.
- Monitor Active Directory, Entra ID, and application login telemetry for authentication anomalies on accounts recently updated through the Admin REST API.
- Review Fine-Grained Admin Permissions assignments monthly and alert on new role grants that include manage-users.
How to Mitigate CVE-2026-97177
Immediate Actions Required
- Apply the fixed Keycloak or Red Hat build of Keycloak release once published in the Red Hat advisory.
- Audit all delegated administrator accounts and remove manage-users from principals that do not require it.
- Rotate credentials for high-value accounts that may have been modified by delegated admins since Fine-Grained Admin Permissions were enabled.
Patch Information
Refer to the Red Hat CVE-2026-97177 security advisory for fixed package versions and errata. Track remediation status through Red Hat Bug #2539965.
Workarounds
- Disable Fine-Grained Admin Permissions where feasible and consolidate user management under full realm administrators until patches are applied.
- Restrict network access to the /admin REST API using a reverse proxy allowlist so only trusted operator hosts can reach the endpoint.
- Implement a WAF rule that blocks PUT requests to /admin/realms/*/users/* containing a credentials field unless the source identity is a trusted full administrator.
# Example reverse proxy restriction (NGINX) limiting Admin REST API exposure
location /admin/ {
allow 10.0.10.0/24; # Trusted admin workstations
deny all;
proxy_pass http://keycloak_upstream;
}
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.