CVE-2025-14778: Red Hat Build Of Keycloak 26.2
Medium severity, CVSS 5.4. EPSS: 0.3% chance of exploitation in the next 30 days.
A flaw was found in Keycloak. A significant Broken Access Control vulnerability exists in the UserManagedPermissionService (UMA Protection API). When updating or deleting a UMA policy associated with multiple resources, the authorization check only verifies the caller's ownership against the first resource in the policy's list. This allows a user (Owner A) who owns one resource (RA) to update a shared policy and modify authorization rules for other resources (e.g., RB) in that same policy, even if those other resources are owned by a different user (Owner B). This constitutes a horizontal privilege escalation.
Affected products
- Red Hat Red Hat Build Of Keycloak 26.2: before 26.2.13-1 (fixed in 26.2.13-1); before 26.2-15 (fixed in 26.2-15)
- Red Hat Red Hat Build Of Keycloak 26.2.13
- Red Hat Red Hat Build Of Keycloak 26.4: before 26.4.9-1 (fixed in 26.4.9-1); before 26.4-11 (fixed in 26.4-11); before 26.4-10 (fixed in 26.4-10)
- Red Hat Red Hat Build Of Keycloak 26.4.9
Published 2026-02-09. Last modified 2026-06-17.