CVE-2025-7784: Red Hat Build Of Keycloak
Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.
A flaw was found in the Keycloak identity and access management system when Fine-Grained Admin Permissions(FGAPv2) are enabled. An administrative user with the manage-users role can escalate their privileges to realm-admin due to improper privilege enforcement. This vulnerability allows unauthorized elevation of access rights, compromising the intended separation of administrative duties and posing a security risk to the realm.
Affected products
- Red Hat Build Of Keycloak: affected versions not specified
Published 2025-07-18. Last modified 2026-06-17.