Identity CVE · Other
CVE-2023-6544Keycloak authorization bypass
high
What broke
Keycloak did not enforce an authorization check on a resource a lesser-privileged caller should not have reached. Red Hat shipped the fix in RHSA-2024:1868 (April 2024) with CVE-2023-6787 and CVE-2023-6717. The 2025 UMA first-resource bug is the same class returning.
Why it matters
An IdP that authenticates correctly and authorizes incorrectly is still an identity failure. Realm roles, client roles, and UMA policies are how Keycloak is access control for a lot of internal apps.
What to do
- Upgrade with the rest of the April 2024 Keycloak set. Do not cherry-pick the SAML CVE.
- Re-test fine-grained admin and UMA policies after the upgrade.
- Treat
realm-managementservice accounts as tier-zero.
Sources
- NVD: CVE-2023-6544
- Red Hat RHSA-2024:1868
Related identity CVEs
Know a primary source we should add, or a patch status that has changed? Email [email protected]. See all briefs in the identity CVE catalog, or volunteer as a CVE Analyst.
Compiled from vendor advisories, NVD, CISA KEV, and public research. CVSS figures can disagree across NVD and the CNA. Confirm affected versions against the vendor advisory before you patch. Independent, community-driven analysis. See the disclaimer.