Описание
A flaw was found in the admin-ui-ext component of Keycloak, which provides extended administrative user interface capabilities. The issue occurs because certain bulk role-removal endpoints fail to perform granular permission checks when deleting role mappings. This allows a delegated administrator with limited permissions to remove highly privileged roles from other users or groups, potentially disrupting administrative access control.
Отчет
The Red Hat Product Security team has assessed the severity of this vulnerability as Moderate, given that it requires the attacker to already possess high-level administrative privileges (delegated administrator) to be exploited. Successful exploitation allows an attacker to remove critical administrative roles from other users, leading to an unauthorized modification of access controls. The vulnerability's root cause is the omission of granular per-role authorization checks in the bulk deletion endpoints of the admin-ui-ext extension.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat JBoss Enterprise Application Platform Expansion Pack | keycloak-rest-admin-ui-ext | Not affected | ||
| Red Hat build of Keycloak 26.6 | rhbk/keycloak-operator-bundle | Fixed | RHSA-2026:50849 | 05.08.2026 |
| Red Hat build of Keycloak 26.6 | rhbk/keycloak-rhel9 | Fixed | RHSA-2026:50849 | 05.08.2026 |
| Red Hat build of Keycloak 26.6 | rhbk/keycloak-rhel9-operator | Fixed | RHSA-2026:50849 | 05.08.2026 |
| Red Hat build of Keycloak 26.6.5 | keycloak-rest-admin-ui-ext | Fixed | RHSA-2026:50848 | 05.08.2026 |
| Red Hat build of Keycloak 26.6.5 | rhbk/keycloak-rhel9 | Fixed | RHSA-2026:50848 | 05.08.2026 |
| Red Hat build of Keycloak 26.6.5 | rhbk-openshift-rhel9/rhbk-openshift-rhel9 | Fixed | RHSA-2026:50848 | 05.08.2026 |
Показывать по
Дополнительная информация
Статус:
EPSS
4.9 Medium
CVSS3
Связанные уязвимости
A flaw was found in the admin-ui-ext component of Keycloak, which provides extended administrative user interface capabilities. The issue occurs because certain bulk role-removal endpoints fail to perform granular permission checks when deleting role mappings. This allows a delegated administrator with limited permissions to remove highly privileged roles from other users or groups, potentially disrupting administrative access control.
A flaw was found in the admin-ui-ext component of Keycloak, which prov ...
A flaw was found in the admin-ui-ext component of Keycloak, which provides extended administrative user interface capabilities. The issue occurs because certain bulk role-removal endpoints fail to perform granular permission checks when deleting role mappings. This allows a delegated administrator with limited permissions to remove highly privileged roles from other users or groups, potentially disrupting administrative access control.
EPSS
4.9 Medium
CVSS3