- What: A privilege escalation vulnerability was found in Keycloak's Fine-Grained Admin Permissions (FGAPv2) feature.
- Impact: An administrative user with the manage-users role can escalate their privileges to realm-admin due to improper privilege enforcement.
Vulnerabilities CVE-2025-7784 Detail Description A flaw was found in the Keycloak identity and access management system when Fine-Grained Admin Permissions(FGAPv2) are enabled. An administrative user with the manage-users role can escalate their privileges to realm-admin due to improper privilege enforcement. This vulnerability allows unauthorized elevation of access rights, compromising the intended separation of administrative duties and posing a security risk to the realm. Metrics NVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed. CVSS 4.0 Severity and Vector Strings: NIST: NVD N/A NVD assessment not yet provided. CVSS 3.x Severity and Vector Strings: CNA: Red Hat, Inc. Base Score: 6.5 MEDIUM Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N CVSS 2.0 Severity and Vector Strings: NIST: NVD Base Score: N/A NVD assessment not yet provided. References to Advisories, Solutions, and Tools By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to [email protected] . URL Source(s) Tag(s) https://access.redhat.com/errata/RHSA-2025:12015 Red Hat, Inc. Vendor Advisory https://access.redhat.com/errata/RHSA-2025:12016 Red Hat, Inc. Vendor Advisory https://access.redhat.com/security/cve/CVE-2025-7784 Red Hat, Inc. Vendor Advisory https://bugzilla.redhat.com/show_bug.cgi?id=2381861 Red Hat, Inc. Issue Tracking Weakness Enumeration CWE-ID CWE Name Source CWE-269 Improper Privilege Management Red Hat, Inc. Known Affected Software Configurations Switch to CPE 2.2 CPEs loading, please wait. Change History 3 change records found show changes Initial Analysis by NIST 8/11/2025 3:16:40 PM Action Type Old Value New Value Added CPE Configuration OR *cpe:2.3:a:redhat:build_of_keycloak:-:*:*:*:-:*:*:* Added Reference Type Red Hat, Inc.: https://access.redhat.com/errata/RHSA-2025:12015 Types: Vendor Advisory Added Reference Type Red Hat, Inc.: https://access.redhat.com/errata/RHSA-2025:12016 Types: Vendor Advisory Added Reference Type Red Hat, Inc.: https://access.redhat.com/security/cve/CVE-2025-7784 Types: Vendor Advisory Added Reference Type Red Hat, Inc.: https://bugzilla.redhat.com/show_bug.cgi?id=2381861 Types: Issue Tracking CVE Modified by Red Hat, Inc. 7/29/2025 7:15:27 AM Action Type Old Value New Value Added Reference https://access.redhat.com/errata/RHSA-2025:12015 Added Reference https://access.redhat.com/errata/RHSA-2025:12016 New CVE Received from Red Hat, Inc. 7/18/2025 10:15:26 AM Action Type Old Value New Value Added Description A flaw was found in the Keycloak identity and access management system when Fine-Grained Admin Permissions(FGAPv2) are enabled. An administrative user with the manage-users role can escalate their privileges to realm-admin due to improper privilege enforcement. This vulnerability allows unauthorized elevation of access rights, compromising the intended separation of administrative duties and posing a security risk to the realm. Added CVSS V3.1 AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N Added CWE CWE-269 Added Reference https://access.redhat.com/security/cve/CVE-2025-7784 Added Reference https://bugzilla.redhat.com/show_bug.cgi?id=2381861 Quick Info CVE Dictionary Entry: CVE-2025-7784 NVD Published Date: 07/18/2025 NVD Last Modified: 08/11/2025 Source: Red Hat, Inc.