Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 4

Количество 4

redhat логотип

CVE-2026-9796

2 месяца назад

A flaw was found in Keycloak. An authenticated administrator with the `manage-clients` role can exploit a Time-of-check to time-of-use (TOCTOU) vulnerability in the name-based admin role checks. This allows the attacker to escalate their privileges to `realm-admin` for all users within the realm, granting them extensive control over the system. The composite role relationship persists even after the attacker's own permissions are revoked and across system reboots.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-9796

2 месяца назад

A flaw was found in Keycloak. An authenticated administrator with the `manage-clients` role can exploit a Time-of-check to time-of-use (TOCTOU) vulnerability in the name-based admin role checks. This allows the attacker to escalate their privileges to `realm-admin` for all users within the realm, granting them extensive control over the system. The composite role relationship persists even after the attacker's own permissions are revoked and across system reboots.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2026-9796

2 месяца назад

A flaw was found in Keycloak. An authenticated administrator with the ...

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-pq65-77rc-7r8c

2 месяца назад

Keycloak has a Time-of-check Time-of-use (TOCTOU) Race Condition

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2026-9796

A flaw was found in Keycloak. An authenticated administrator with the `manage-clients` role can exploit a Time-of-check to time-of-use (TOCTOU) vulnerability in the name-based admin role checks. This allows the attacker to escalate their privileges to `realm-admin` for all users within the realm, granting them extensive control over the system. The composite role relationship persists even after the attacker's own permissions are revoked and across system reboots.

CVSS3: 6.5
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-9796

A flaw was found in Keycloak. An authenticated administrator with the `manage-clients` role can exploit a Time-of-check to time-of-use (TOCTOU) vulnerability in the name-based admin role checks. This allows the attacker to escalate their privileges to `realm-admin` for all users within the realm, granting them extensive control over the system. The composite role relationship persists even after the attacker's own permissions are revoked and across system reboots.

CVSS3: 6.5
0%
Низкий
2 месяца назад
debian логотип
CVE-2026-9796

A flaw was found in Keycloak. An authenticated administrator with the ...

CVSS3: 6.5
0%
Низкий
2 месяца назад
github логотип
GHSA-pq65-77rc-7r8c

Keycloak has a Time-of-check Time-of-use (TOCTOU) Race Condition

CVSS3: 6.5
0%
Низкий
2 месяца назад

Уязвимостей на страницу