
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-3121 is a privilege escalation vulnerability in Keycloak (org.keycloak/keycloak-services) caused by incorrect privilege assignment in the manage-clients permission. An administrator holding the manage-clients role can exploit a misconfiguration where this permission is functionally equivalent to manage-permissions, enabling them to escalate privileges and gain control over roles, users, or other administrative functions within the realm. The flaw was first reported on February 24, 2026, and patches were released on April 2, 2026. Affected products include Red Hat build of Keycloak, Red Hat Single Sign-On 7.0, Red Hat JBoss Enterprise Application Platform 8.0.0, and the JBoss EAP Expansion Pack. The CVSS v3.1 base score is 7.2 (High) (Red Hat CVE, Red Hat Bugzilla).
The root cause is classified as CWE-266 (Incorrect Privilege Assignment): the manage-clients permission in Keycloak inadvertently grants the same access as manage-permissions, allowing an administrator with only client management rights to interact with the permissions client and escalate their privileges. Exploitation requires two preconditions: the attacker must already hold the manage-clients administrator role in a Keycloak realm, and admin permissions must be enabled at the realm level (via Realm Settings → General). Once these conditions are met, the attacker can use the permissions client to assign themselves or other administrators elevated rights over roles, users, or other administrative functions. No public PoC code has been identified, but the Red Hat Bugzilla entry includes a detailed reproducer (Red Hat Bugzilla, Red Hat CVE).
Successful exploitation allows a limited administrator to escalate their privileges to full realm administrative control, compromising confidentiality, integrity, and availability of the Keycloak realm. An attacker could reassign roles, modify or delete users, alter authentication policies, or take over other administrative accounts, potentially enabling lateral movement across all applications and services relying on the affected Keycloak realm for authentication. The scope is limited to the affected realm, but in multi-tenant or enterprise deployments, this could expose sensitive identity and access management data across many integrated applications (Red Hat CVE, Red Hat Bugzilla).
manage-clients, view-clients, and list-clients permissions within the realm.manage-clients is treated as equivalent to manage-permissions to assign elevated permissions — such as manage-roles, manage-users, or full realm admin rights — to the attacker's account or another controlled account.manage-clients-privileged user performing permission assignment operations (e.g., PERMISSION resource type events) outside their expected scope; unexpected changes to admin role assignments in realm audit logs.manage-roles, manage-users, or other elevated permission scopes initiated by accounts that should only hold manage-clients.Red Hat released patched versions on April 2, 2026: Red Hat build of Keycloak 26.4.11 (packages via RHSA-2026:6477 and container images via RHSA-2026:6478). Upstream Keycloak 26.5.6 also addresses this issue. As an immediate workaround, administrators should disable admin permissions at the realm level (Realm Settings → General → Admin Permissions: Disabled) if not required, or audit and restrict which accounts hold the manage-clients permission. Upgrading to the patched release is the recommended long-term remediation (RHSA-2026:6477, RHSA-2026:6478, Red Hat Bugzilla).
Red Hat classified the advisory (RHSA-2026:6477 and RHSA-2026:6478) as Important severity, bundling CVE-2026-3121 with 14 other Keycloak security fixes in the 26.4.11 update. No notable independent researcher commentary or significant social media discussion has been identified beyond standard CVE tracking and aggregator coverage (RHSA-2026:6477, RHSA-2026:6478).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."