Количество 4
Количество 4
CVE-2026-9796
A flaw was found in Keycloak. An authenticated administrator with the `manage-clients` role can exploit a Time-of-check to time-of-use (TOCTOU) vulnerability in the name-based admin role checks. This allows the attacker to escalate their privileges to `realm-admin` for all users within the realm, granting them extensive control over the system. The composite role relationship persists even after the attacker's own permissions are revoked and across system reboots.
CVE-2026-9796
A flaw was found in Keycloak. An authenticated administrator with the `manage-clients` role can exploit a Time-of-check to time-of-use (TOCTOU) vulnerability in the name-based admin role checks. This allows the attacker to escalate their privileges to `realm-admin` for all users within the realm, granting them extensive control over the system. The composite role relationship persists even after the attacker's own permissions are revoked and across system reboots.
CVE-2026-9796
A flaw was found in Keycloak. An authenticated administrator with the ...
GHSA-pq65-77rc-7r8c
Keycloak has a Time-of-check Time-of-use (TOCTOU) Race Condition
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-9796 A flaw was found in Keycloak. An authenticated administrator with the `manage-clients` role can exploit a Time-of-check to time-of-use (TOCTOU) vulnerability in the name-based admin role checks. This allows the attacker to escalate their privileges to `realm-admin` for all users within the realm, granting them extensive control over the system. The composite role relationship persists even after the attacker's own permissions are revoked and across system reboots. | CVSS3: 6.5 | 0% Низкий | 2 месяца назад | |
CVE-2026-9796 A flaw was found in Keycloak. An authenticated administrator with the `manage-clients` role can exploit a Time-of-check to time-of-use (TOCTOU) vulnerability in the name-based admin role checks. This allows the attacker to escalate their privileges to `realm-admin` for all users within the realm, granting them extensive control over the system. The composite role relationship persists even after the attacker's own permissions are revoked and across system reboots. | CVSS3: 6.5 | 0% Низкий | 2 месяца назад | |
CVE-2026-9796 A flaw was found in Keycloak. An authenticated administrator with the ... | CVSS3: 6.5 | 0% Низкий | 2 месяца назад | |
GHSA-pq65-77rc-7r8c Keycloak has a Time-of-check Time-of-use (TOCTOU) Race Condition | CVSS3: 6.5 | 0% Низкий | 2 месяца назад |
Уязвимостей на страницу