Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-11986

Опубликовано: 11 июн. 2026
Источник: redhat
CVSS3: 4.9
EPSS Низкий

Описание

A flaw was found in the admin-ui-ext component of Keycloak, which provides extended administrative user interface capabilities. The issue occurs because certain bulk role-removal endpoints fail to perform granular permission checks when deleting role mappings. This allows a delegated administrator with limited permissions to remove highly privileged roles from other users or groups, potentially disrupting administrative access control.

Отчет

The Red Hat Product Security team has assessed the severity of this vulnerability as Moderate, given that it requires the attacker to already possess high-level administrative privileges (delegated administrator) to be exploited. Successful exploitation allows an attacker to remove critical administrative roles from other users, leading to an unauthorized modification of access controls. The vulnerability's root cause is the omission of granular per-role authorization checks in the bulk deletion endpoints of the admin-ui-ext extension.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss Enterprise Application Platform Expansion Packkeycloak-rest-admin-ui-extNot affected
Red Hat build of Keycloak 26.6rhbk/keycloak-operator-bundleFixedRHSA-2026:5084905.08.2026
Red Hat build of Keycloak 26.6rhbk/keycloak-rhel9FixedRHSA-2026:5084905.08.2026
Red Hat build of Keycloak 26.6rhbk/keycloak-rhel9-operatorFixedRHSA-2026:5084905.08.2026
Red Hat build of Keycloak 26.6.5keycloak-rest-admin-ui-extFixedRHSA-2026:5084805.08.2026
Red Hat build of Keycloak 26.6.5rhbk/keycloak-rhel9FixedRHSA-2026:5084805.08.2026
Red Hat build of Keycloak 26.6.5rhbk-openshift-rhel9/rhbk-openshift-rhel9FixedRHSA-2026:5084805.08.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-425
https://bugzilla.redhat.com/show_bug.cgi?id=2487906keycloak-rest-admin-ui-ext: Authorization Bypass vulnerability in the admin-ui-ext bulk role-mapping-delete endpoints of Keycloak

EPSS

Процентиль: 23%
0.00301
Низкий

4.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.9
nvd
2 месяца назад

A flaw was found in the admin-ui-ext component of Keycloak, which provides extended administrative user interface capabilities. The issue occurs because certain bulk role-removal endpoints fail to perform granular permission checks when deleting role mappings. This allows a delegated administrator with limited permissions to remove highly privileged roles from other users or groups, potentially disrupting administrative access control.

CVSS3: 4.9
debian
2 месяца назад

A flaw was found in the admin-ui-ext component of Keycloak, which prov ...

CVSS3: 4.9
github
2 месяца назад

A flaw was found in the admin-ui-ext component of Keycloak, which provides extended administrative user interface capabilities. The issue occurs because certain bulk role-removal endpoints fail to perform granular permission checks when deleting role mappings. This allows a delegated administrator with limited permissions to remove highly privileged roles from other users or groups, potentially disrupting administrative access control.

EPSS

Процентиль: 23%
0.00301
Низкий

4.9 Medium

CVSS3