Authorization Flaw in Keycloak's RoleContainerResource Component
CVE-2026-16105

4.9MEDIUM

What is CVE-2026-16105?

A vulnerability has been identified in the RoleContainerResource component of Keycloak whereby certain name-based endpoints within the admin REST API fail to enforce proper authorization checks when managing composite roles. This oversight allows a delegated administrator, equipped with manage-realm permissions, to potentially remove critical child roles from built-in admin roles. Such actions may lead to significant disruptions in administrative functions within an individual realm, compromising the integrity and management capabilities of the key security features in Keycloak.

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank localhost-detect for reporting this issue.
.