Authentication Bypass by Alternate Name Affecting org.keycloak:keycloak-services package, versions [0,26.5.6)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.04% (12th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-ORGKEYCLOAK-14427054
  • published16 Dec 2025
  • disclosed16 Dec 2025
  • creditJoshua Rogers

Introduced: 16 Dec 2025

CVE-2025-14777  (opens in a new tab)
CWE-289  (opens in a new tab)

How to fix?

Upgrade org.keycloak:keycloak-services to version 26.5.6 or higher.

Overview

org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services.

Affected versions of this package are vulnerable to Authentication Bypass by Alternate Name via the ResourceSetService and PermissionTicketService modules due to improper verification of resourceServer ID. An attacker can access and modify resources belonging to other clients by supplying a valid resourceId in the admin API endpoints, bypassing proper authorization checks.

CVSS Base Scores

version 4.0
version 3.1