{"id":"ECHO-73ab-600d-62be","summary":"Caught by Cursor Bugbot review on PR #19827: the real vulnerability\n(GHSA-7xf9-4jfc-wgm4) is specific to Fine-Grained Admin Permissions\nV2's RealmPermissionsV2 treating manage-clients as equivalent to\nmanaging the special \"admin-permissions\" client, which then grants\nrealm-wide admin power. RealmPermissionsV2 and the admin-permissions\nclient concept do not exist in 25.0.6 — its older\nRealmPermissions.canManageAuthorizationDefault() has no\nper-ResourceServer parameter at all (it's a single, undifferentiated\nrealm-wide check), so there is no \"is this the special\nadmin-permissions client\" distinction for a narrow, upstream-faithful\nfix to attach to. An earlier patch here unconditionally removed\nMANAGE_CLIENTS from that check to close the described escalation, but\nthat changes intended authorization behavior for every regular\nclient's authorization management, not just a vulnerable path\n(upstream's real fix leaves the MANAGE_CLIENTS grant intact for\nnon-admin-permissions clients) — reverted.\n","modified":"2026-08-31T15:15:02.917702952Z","published":"2026-08-30T16:45:31.557Z","withdrawn":"2026-08-31T14:30:19.360Z","upstream":["CVE-2026-3121","GHSA-7xf9-4jfc-wgm4"],"references":[{"type":"WEB","url":"https://advisory.echohq.com/cve/CVE-2026-3121"}],"affected":[{"package":{"name":"keycloak-25","ecosystem":"Echo","purl":"pkg:deb/echo/keycloak-25"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"25.0.6+e2"}]}],"database_specific":{"source":"https://advisory.echohq.com/osv/ECHO-73ab-600d-62be.json"}},{"package":{"name":"org.keycloak:keycloak-services","ecosystem":"Echo:Maven","purl":"pkg:maven/org.keycloak/keycloak-services"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"database_specific":{"source":"https://advisory.echohq.com/osv/ECHO-73ab-600d-62be.json"}}],"schema_version":"1.9.0"}