CVE-2026-3121
published 2026-03-26CVE-2026-3121: A flaw was found in Keycloak. An administrator with `manage-clients` permission can exploit a misconfiguration where this permission is equivalent to…
PriorityP346high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
EPSS
0.47%
37.7th percentile
A flaw was found in Keycloak. An administrator with `manage-clients` permission can exploit a misconfiguration where this permission is equivalent to `manage-permissions`. This allows the administrator to escalate privileges and gain control over roles, users, or other administrative functions within the realm. This privilege escalation can occur when admin permissions are enabled at the realm level.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | single_sign-on | — | — |
CVSS provenance
nvdv3.17.2HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Keycloak: manage-clients permission escalates to full realm admin access
ghsa·2026-03-26
CVE-2026-3121 [MEDIUM] CWE-266 Keycloak: manage-clients permission escalates to full realm admin access
Keycloak: manage-clients permission escalates to full realm admin access
A flaw was found in Keycloak. An administrator with `manage-clients` permission can exploit a misconfiguration where this permission is equivalent to `manage-permissions`. This allows the administrator to escalate privileges and gain control over roles, users, or other administrative functions within the realm. This privilege escalation can occur when admin permissions are enabled at the realm level.
OSV
Keycloak: manage-clients permission escalates to full realm admin access
osv·2026-03-26
CVE-2026-3121 [MEDIUM] Keycloak: manage-clients permission escalates to full realm admin access
Keycloak: manage-clients permission escalates to full realm admin access
A flaw was found in Keycloak. An administrator with `manage-clients` permission can exploit a misconfiguration where this permission is equivalent to `manage-permissions`. This allows the administrator to escalate privileges and gain control over roles, users, or other administrative functions within the realm. This privilege escalation can occur when admin permissions are enabled at the realm level.
Red Hat
keycloak: org.keycloak/keycloak-services: Keycloak: Privilege escalation via manage-clients permission
vendor_redhat·2026-02-24·CVSS 6.5
CVE-2026-3121 [MEDIUM] CWE-266 keycloak: org.keycloak/keycloak-services: Keycloak: Privilege escalation via manage-clients permission
keycloak: org.keycloak/keycloak-services: Keycloak: Privilege escalation via manage-clients permission
A flaw was found in Keycloak. An administrator with `manage-clients` permission can exploit a misconfiguration where this permission is equivalent to `manage-permissions`. This allows the administrator to escalate privileges and gain control over roles, users, or other administrative functions within the realm. This privilege escalation can occur when admin permissions are enabled at the realm level.
A flaw was found in Keycloak. An administrator with `manage-clients` permission can exploit a misconfiguration where this permission is equivalent to `manage-permissions`. This allows the administrator to escalate privileges and gain control over roles, users, or other administrative functi
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-3121 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.5
CVE-2026-3121 [MEDIUM] CVE-2026-3121 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-3121 :
Java vulnerability analysis and mitigation
manage-clients
manage-permissions
Source : NVD
## 7.2
Score
Published March 26, 2026
Severity HIGH
CNA Score 6.5
Affected Technologies
Java
Keycloak
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 8.6
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:redhat:jboss_enterprise_application_platform
org.keycloak:keycloak-services
Sources
Maven Severity MEDIUM Has Fix Added at: Mar 29, 2026
MinimOS Severity HIGH Has Fix Added at: Mar 31, 2026
Linux Severity HIGH No Fix Added at: Apr 02, 2026
Windows Severity HIGH No Fix Added at: Apr 02, 2026
Linux Severity HIGH No Fix Added at: Apr 05, 2026
Wiz
CVE-2026-4366 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.7
CVE-2026-4366 [HIGH] CVE-2026-4366 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-4366 :
JBoss EAP vulnerability analysis and mitigation
A flaw was identified in Keycloak, an identity and access management solution, where it improperly follows HTTP redirects when processing certain client configuration requests. This behavior allows an attacker to trick the server into making unintended requests to internal or restricted resources. As a result, sensitive internal services such as cloud metadata endpoints could be accessed. This issue may lead to information disclosure and enable attackers to map internal network infrastructure.
Source : NVD
## 5.8
Score
Published March 18, 2026
Severity MEDIUM
CNA Score 5.8
Affected Technologies
JBoss EAP
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitati
2026-03-26
Published