---
id: CVE-2026-96448
title: >-
  A flaw was found in the Fine-Grained Admin Permissions (FGAP v2) feature of
  Keycloak, an identity and access management solution
summary: >-
  A flaw was found in the Fine-Grained Admin Permissions (FGAP v2) feature of
  Keycloak, an identity and access management solution. The issue occurs when
  the system checks if a delegated administrator has permission to assign a
  specific ro…
severity: medium
cvss: 6.6
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-285
vendor: Red Hat
product: keycloak-services
affected:
  - keycloak-services (all versions)
  - rhbk/keycloak-rhel9 (all versions)
  - keycloak-services
published: '2026-09-25'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T13:26:09.190'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-96448'
references:
  - url: 'https://access.redhat.com/security/cve/CVE-2026-96448'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2539291'
    label: secalert@redhat.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-25T08:01:56.750Z'
---

## Overview

A flaw was found in the Fine-Grained Admin Permissions (FGAP v2) feature of Keycloak, an identity and access management solution. The issue occurs when the system checks if a delegated administrator has permission to assign a specific role to a user. Because the check does not look inside composite roles to see what other permissions they contain, an administrator with limited rights can assign a role that secretly includes full administrative control. This allows the attacker to gain complete management access over the entire realm.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
