CVE-2026-3121
Java vulnerability analysis and mitigation

Overview

CVE-2026-3121 is a privilege escalation vulnerability in Keycloak (org.keycloak/keycloak-services) caused by incorrect privilege assignment in the manage-clients permission. An administrator holding the manage-clients role can exploit a misconfiguration where this permission is functionally equivalent to manage-permissions, enabling them to escalate privileges and gain control over roles, users, or other administrative functions within the realm. The flaw was first reported on February 24, 2026, and patches were released on April 2, 2026. Affected products include Red Hat build of Keycloak, Red Hat Single Sign-On 7.0, Red Hat JBoss Enterprise Application Platform 8.0.0, and the JBoss EAP Expansion Pack. The CVSS v3.1 base score is 7.2 (High) (Red Hat CVE, Red Hat Bugzilla).

Technical details

The root cause is classified as CWE-266 (Incorrect Privilege Assignment): the manage-clients permission in Keycloak inadvertently grants the same access as manage-permissions, allowing an administrator with only client management rights to interact with the permissions client and escalate their privileges. Exploitation requires two preconditions: the attacker must already hold the manage-clients administrator role in a Keycloak realm, and admin permissions must be enabled at the realm level (via Realm Settings → General). Once these conditions are met, the attacker can use the permissions client to assign themselves or other administrators elevated rights over roles, users, or other administrative functions. No public PoC code has been identified, but the Red Hat Bugzilla entry includes a detailed reproducer (Red Hat Bugzilla, Red Hat CVE).

Impact

Successful exploitation allows a limited administrator to escalate their privileges to full realm administrative control, compromising confidentiality, integrity, and availability of the Keycloak realm. An attacker could reassign roles, modify or delete users, alter authentication policies, or take over other administrative accounts, potentially enabling lateral movement across all applications and services relying on the affected Keycloak realm for authentication. The scope is limited to the affected realm, but in multi-tenant or enterprise deployments, this could expose sensitive identity and access management data across many integrated applications (Red Hat CVE, Red Hat Bugzilla).

Exploitation steps

  1. Identify target realm: Confirm that the target Keycloak realm has admin permissions enabled (Realm Settings → General → Admin Permissions: Enabled).
  2. Obtain manage-clients access: Acquire or compromise an administrator account that has been granted manage-clients, view-clients, and list-clients permissions within the realm.
  3. Access the permissions client: Using the compromised account, navigate to or interact with the permissions client (the internal Keycloak client used for fine-grained admin permissions management).
  4. Escalate privileges: Leverage the misconfiguration where manage-clients is treated as equivalent to manage-permissions to assign elevated permissions — such as manage-roles, manage-users, or full realm admin rights — to the attacker's account or another controlled account.
  5. Achieve full realm control: With escalated permissions, perform unauthorized administrative actions including modifying user roles, resetting credentials, altering authentication flows, or accessing sensitive realm configuration data (Red Hat Bugzilla).

Indicators of compromise

  • Logs: Keycloak admin event logs showing a manage-clients-privileged user performing permission assignment operations (e.g., PERMISSION resource type events) outside their expected scope; unexpected changes to admin role assignments in realm audit logs.
  • Logs: Admin events reflecting modifications to manage-roles, manage-users, or other elevated permission scopes initiated by accounts that should only hold manage-clients.
  • Behavioral: Unexpected creation or modification of realm roles, user accounts, or authentication policies by accounts with limited administrative privileges; sudden appearance of new admin-level accounts or role bindings not initiated by a full realm administrator.

Mitigation and workarounds

Red Hat released patched versions on April 2, 2026: Red Hat build of Keycloak 26.4.11 (packages via RHSA-2026:6477 and container images via RHSA-2026:6478). Upstream Keycloak 26.5.6 also addresses this issue. As an immediate workaround, administrators should disable admin permissions at the realm level (Realm Settings → General → Admin Permissions: Disabled) if not required, or audit and restrict which accounts hold the manage-clients permission. Upgrading to the patched release is the recommended long-term remediation (RHSA-2026:6477, RHSA-2026:6478, Red Hat Bugzilla).

Community reactions

Red Hat classified the advisory (RHSA-2026:6477 and RHSA-2026:6478) as Important severity, bundling CVE-2026-3121 with 14 other Keycloak security fixes in the 26.4.11 update. No notable independent researcher commentary or significant social media discussion has been identified beyond standard CVE tracking and aggregator coverage (RHSA-2026:6477, RHSA-2026:6478).

Additional resources


SourceThis report was generated using AI

Related Java vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-p279-2cqp-84jgCRITICAL9.6
  • Java logoJava
  • org.openidentityplatform.opendj:opendj-server-legacy
NoYesJul 24, 2026
GHSA-fp43-vj7g-pg92HIGH7.5
  • Java logoJava
  • org.omnifaces:omnifaces
NoYesJul 24, 2026
GHSA-7ppr-r889-mcf2HIGH7.5
  • Java logoJava
  • org.http4s:http4s-blaze-server_2.12
NoYesJul 24, 2026
GHSA-mhvj-jhpq-885vHIGH7.4
  • Java logoJava
  • org.http4s:http4s-blaze-server_2.13
NoYesJul 24, 2026
GHSA-46q4-43ph-c6frHIGH7.4
  • Java logoJava
  • org.http4s:blaze-http_2.12
NoYesJul 24, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management