Looking for the vulnerability index of Invicti's legacy products?
Jboss EAP Incorrect Privilege Assignment Vulnerability - CVE-2026-3121 - Vulnerability Database

Jboss EAP Incorrect Privilege Assignment Vulnerability - CVE-2026-3121

High
Reference: CVE-2026-3121
Title: Jboss EAP Incorrect Privilege Assignment Vulnerability
Overview:

A flaw was found in Keycloak. An administrator with manage-clients permission can exploit a misconfiguration where this permission is equivalent to manage-permissions. This allows the administrator to escalate privileges and gain control over roles users or other administrative functions within the realm. This privilege escalation can occur when admin permissions are enabled at the realm level.