« Volver al listado

CVE-2026-3121

Estado: ModificadaAlta (7.2)—

A flaw was found in Keycloak. An administrator with `manage-clients` permission can exploit a misconfiguration where this permission is equivalent to `manage-permissions`. This allows the administrator to escalate privileges and gain control over roles, users, or other administrative functions within the realm. This privilege escalation can occur when admin permissions are enabled at the realm level.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vector CVSS con PR:H y AV:N indica servicios remotos con privilegios administrativos. Misconfiguration de permisos permite escalada de privilegios (T1068) desde rol limitado a control total del realm, manipulación de cuentas y políticas de autenticación.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (4)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-3121",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-3121",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-03-30T13:58:46.558680Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "secalert@redhat.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.2,
        "exploitabilityScore": 1.2
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.2,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.2
      }
    ]
  },
  "affected": [
    {
      "source": "secalert@redhat.com",
      "affectedData": [
        {
          "cpes": [
            "cpe:/a:redhat:build_keycloak:26.4::el9"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat build of Keycloak 26.4",
          "versions": [
            {
              "status": "unaffected",
              "version": "26.4.11-1",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "rhbk/keycloak-operator-bundle",
          "collectionURL": "https://catalog.redhat.com/software/containers/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:build_keycloak:26.4::el9"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat build of Keycloak 26.4",
          "versions": [
            {
              "status": "unaffected",
              "version": "26.4-14",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "rhbk/keycloak-rhel9",
          "collectionURL": "https://catalog.redhat.com/software/containers/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:build_keycloak:26.4::el9"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat build of Keycloak 26.4",
          "versions": [
            {
              "status": "unaffected",
              "version": "26.4-14",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "rhbk/keycloak-rhel9-operator",
          "collectionURL": "https://catalog.redhat.com/software/containers/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:build_keycloak:26.4::el9"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat build of Keycloak 26.4.11",
          "packageName": "rhbk/keycloak-rhel9",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "unaffected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:jboss_enterprise_application_platform:8"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat JBoss Enterprise Application Platform 8",
          "packageName": "keycloak-services",
          "collectionURL": "https://access.redhat.com/jbossnetwork/restricted/listSoftware.html",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:jbosseapxp"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat JBoss Enterprise Application Platform Expansion Pack",
          "packageName": "keycloak-services",
          "collectionURL": "https://access.redhat.com/jbossnetwork/restricted/listSoftware.html",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:red_hat_single_sign_on:7"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat Single Sign-On 7",
          "packageName": "keycloak-services",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-03-26T19:17:06.213",
  "references": [
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:6477",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:6478",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://access.redhat.com/security/cve/CVE-2026-3121",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2442277",
      "tags": [
        "Issue Tracking",
        "Vendor Advisory"
      ],
      "source": "secalert@redhat.com"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "secalert@redhat.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-266"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A flaw was found in Keycloak. An administrator with `manage-clients` permission can exploit a misconfiguration where this permission is equivalent to `manage-permissions`. This allows the administrator to escalate privileges and gain control over roles, users, or other administrative functions within the realm. This privilege escalation can occur when admin permissions are enabled at the realm level."
    },
    {
      "lang": "es",
      "value": "Se encontró un fallo en Keycloak. Un administrador con permiso 'manage-clients' puede explotar una mala configuración donde este permiso es equivalente a 'manage-permissions'. Esto permite al administrador escalar privilegios y obtener control sobre roles, usuarios u otras funciones administrativas dentro del ámbito. Esta escalada de privilegios puede ocurrir cuando los permisos de administrador están habilitados a nivel de ámbito."
    }
  ],
  "lastModified": "2026-06-17T10:43:04.877",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:redhat:build_of_keycloak:-:*:*:*:-:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E5C930CB-4EAD-497B-A44B-D880F2A1F85B"
            },
            {
              "criteria": "cpe:2.3:a:redhat:jboss_enterprise_application_platform:8.0.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0D8BC03A-4198-4488-946B-3F6B43962942"
            },
            {
              "criteria": "cpe:2.3:a:redhat:jboss_enterprise_application_platform_expansion_pack:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0A24CBFB-4900-47A5-88D2-A44C929603DC"
            },
            {
              "criteria": "cpe:2.3:a:redhat:single_sign-on:7.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9EFEC7CA-8DDA-48A6-A7B6-1F1D14792890"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secalert@redhat.com"
}