CVE-2026-97177
MEDIUM
NVD
CVSS Score
6.6
Severity
MEDIUM
Published
Sep 24, 2026
Vendor
unknown
Description
A flaw was found in the user update mechanism of the Keycloak Admin REST API. When Fine-Grained Admin Permissions are enabled, the system fails to check for specific password reset authorizations during a general user profile update. This allows a delegated administrator, who should be restricted from resetting passwords, to change a user's credentials and take over their account.