Back to CVE List

CVE-2026-11986

MEDIUM SEVERITY

CVSS Score & Metrics

Base Score
4.9 / 10
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N

Vulnerability Description

A flaw was found in the admin-ui-ext component of Keycloak, which provides extended administrative user interface capabilities. The issue occurs because certain bulk role-removal endpoints fail to perform granular permission checks when deleting role mappings. This allows a delegated administrator with limited permissions to remove highly privileged roles from other users or groups, potentially disrupting administrative access control.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-425
Source
NVD
Vendor
Red Hat
Product
Red Hat Build of Keycloak, Red Hat JBoss Enterprise Application Platform Expansion Pack

External References

Discussion (0)

Add Comment

No comments yet. Be the first!