CVE-2026-17526: Red Hat Build Of Keycloak 26.4

High severity, CVSS 7.2. EPSS: 0.5% chance of exploitation in the next 30 days.

Keycloak is an open-source identity and access management solution. A vulnerability was discovered where a user with the impersonation role can impersonate a realm administrator. This allows the attacker to gain full administrative control over the realm, including the ability to manage users, clients, and roles.

Affected products

  • Red Hat Red Hat Build Of Keycloak 26.4: before 26.4.16-2 (fixed in 26.4.16-2); before 26.4-26 (fixed in 26.4-26)
  • Red Hat Red Hat Build Of Keycloak 26.4.16
  • Red Hat Red Hat Build Of Keycloak 26.6: before 26.6.7-3 (fixed in 26.6.7-3); before 26.6-20 (fixed in 26.6-20)
  • Red Hat Red Hat Build Of Keycloak 26.6.7
  • Red Hat Red Hat Data Grid 8
  • Red Hat Red Hat JBoss Enterprise Application Platform Expansion Pack
  • Red Hat Red Hat Single Sign-On 7

Published 2026-09-16. Last modified 2026-09-16.