HomeRedhatCVE-2025-7784

CVE-2025-7784

MEDIUM
6.5CVSS
Published: 2025-07-18
Updated: 2025-08-11
AI Analysis

Description

A flaw was found in the Keycloak identity and access management system when Fine-Grained Admin Permissions(FGAPv2) are enabled. An administrative user with the manage-users role can escalate their privileges to realm-admin due to improper privilege enforcement. This vulnerability allows unauthorized elevation of access rights, compromising the intended separation of administrative duties and posing a security risk to the realm.

CVSS Metrics

Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
Attack Vector
network
Complexity
low
Privileges
high
User Action
none
Scope
unchanged
Confidentiality
high
Integrity
high
Availability
none
Weaknesses
CWE-269

Metadata

Primary Vendor
REDHAT
Published
7/18/2025
Last Modified
8/11/2025
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

redhat : build_of_keycloak

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief

CVE-CVE-2025-7784 | MEDIUM Severity | CVEDatabase.com | CVEDatabase.com