A flaw was found in the admin-ui-ext component of Keycloak, which provides extended administrative user interface capabilities. The issue occurs because certain bulk role-removal endpoints fail to perform granular permission checks when deleting role mappings. This allows a delegated administrator with limited permissions to remove highly privileged roles from other users or groups, potentially disrupting administrative access control.
Metrics
Affected Vendors & Products
References
History
Tue, 11 Aug 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:redhat:build_of_keycloak:*:*:*:*:*:*:*:* |
Wed, 05 Aug 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:build_keycloak:26.6::el9 | |
| References |
|
Fri, 12 Jun 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat build Of Keycloak
Redhat jboss Enterprise Application Platform Expansion Pack |
|
| Vendors & Products |
Redhat build Of Keycloak
Redhat jboss Enterprise Application Platform Expansion Pack |
Fri, 12 Jun 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Thu, 11 Jun 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 11 Jun 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in the admin-ui-ext component of Keycloak, which provides extended administrative user interface capabilities. The issue occurs because certain bulk role-removal endpoints fail to perform granular permission checks when deleting role mappings. This allows a delegated administrator with limited permissions to remove highly privileged roles from other users or groups, potentially disrupting administrative access control. | |
| Title | Keycloak-rest-admin-ui-ext: authorization bypass vulnerability in the admin-ui-ext bulk role-mapping-delete endpoints of keycloak | |
| First Time appeared |
Redhat
Redhat build Keycloak Redhat jbosseapxp |
|
| Weaknesses | CWE-425 | |
| CPEs | cpe:/a:redhat:build_keycloak: cpe:/a:redhat:jbosseapxp |
|
| Vendors & Products |
Redhat
Redhat build Keycloak Redhat jbosseapxp |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published: 2026-06-11T16:47:11.862Z
Updated: 2026-08-05T18:45:38.357Z
Reserved: 2026-06-11T14:18:10.409Z
Link: CVE-2026-11986
Updated: 2026-06-11T18:49:48.522Z
Status : Analyzed
Published: 2026-06-11T18:16:25.033
Modified: 2026-08-11T12:58:09.007
Link: CVE-2026-11986