# Keycloak authorization bypass

Source: https://startwithidentity.com/cves/cve-2023-6544/
Last updated: 2026-08-29
License: content by Start with Identity. Cite the source URL.

---

## What broke

[Keycloak](https://startwithidentity.com/vendors/open-source/keycloak/) did not enforce an authorization check on a resource a lesser-privileged caller should not have reached. Red Hat shipped the fix in RHSA-2024:1868 (April 2024) with [CVE-2023-6787](https://startwithidentity.com/cves/cve-2023-6787/) and [CVE-2023-6717](https://startwithidentity.com/cves/cve-2023-6717/). The 2025 [UMA first-resource](https://startwithidentity.com/cves/cve-2025-14778/) bug is the same class returning.

## Why it matters

An IdP that authenticates correctly and authorizes incorrectly is still an identity failure. Realm roles, client roles, and UMA policies are how Keycloak *is* access control for a lot of internal apps.

## What to do

- Upgrade with the rest of the April 2024 Keycloak set. Do not cherry-pick the SAML CVE.
- Re-test fine-grained admin and UMA policies after the upgrade.
- Treat `realm-management` service accounts as tier-zero.

## After you patch

Patching closes the entry point. It does not remove access an attacker established through it.

- **Revoke sessions and API tokens** on the affected system rather than only resetting passwords.
- **Audit accounts, tokens, and administrative changes** made during the exposure window.
- **Rotate credentials the system stored or could reach**, including directory service accounts and integration keys. See [secrets rotation](https://startwithidentity.com/glossary/secrets-rotation/).
- **Treat the system as a pivot**: whatever it could authenticate to is in scope until you have checked it.

## Sources

- [NVD: CVE-2023-6544](https://nvd.nist.gov/vuln/detail/CVE-2023-6544)
- Red Hat RHSA-2024:1868
