Role-Removal Permission Flaw in Keycloak's Admin User Interface
CVE-2026-11986
4.9MEDIUM
What is CVE-2026-11986?
A security issue has been identified in the admin-ui-ext component of Keycloak. Specifically, the flaw arises from insufficient permission checks on certain bulk role-removal endpoints. As a result, delegated administrators who possess limited permissions may exploit this vulnerability to remove highly privileged roles from users or groups. This compromise could severely impact administrative access control, leading to unauthorized access and potential disruption in the management of user roles.
References
CVSS V3.1
Score:
4.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Wesley "Alardiians" Colquitt (Byteshyft Studios) for reporting this issue.