Start with Identity
Identity CVE · Other

CVE-2023-6544Keycloak authorization bypass

high
Product: KeycloakVendor: Red HatDisclosed: 2024-04-16Status: PatchedNVD ↗

What broke

Keycloak did not enforce an authorization check on a resource a lesser-privileged caller should not have reached. Red Hat shipped the fix in RHSA-2024:1868 (April 2024) with CVE-2023-6787 and CVE-2023-6717. The 2025 UMA first-resource bug is the same class returning.

Why it matters

An IdP that authenticates correctly and authorizes incorrectly is still an identity failure. Realm roles, client roles, and UMA policies are how Keycloak is access control for a lot of internal apps.

What to do

  • Upgrade with the rest of the April 2024 Keycloak set. Do not cherry-pick the SAML CVE.
  • Re-test fine-grained admin and UMA policies after the upgrade.
  • Treat realm-management service accounts as tier-zero.

Sources

Know a primary source we should add, or a patch status that has changed? Email [email protected]. See all briefs in the identity CVE catalog, or volunteer as a CVE Analyst.
Compiled from vendor advisories, NVD, CISA KEV, and public research. CVSS figures can disagree across NVD and the CNA. Confirm affected versions against the vendor advisory before you patch. Independent, community-driven analysis. See the disclaimer.