A flaw was found in the admin-ui-ext component of Keycloak, which provides extended administrative user interface capabilities. The issue occurs because certain bulk role-removal endpoints fail to perform granular permission checks when deleting role mappings. This allows a delegated administrator with limited permissions to remove highly privileged roles from other users or groups, potentially disrupting administrative access control.
Metrics
Affected Vendors & Products
References
History
Thu, 11 Jun 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 11 Jun 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in the admin-ui-ext component of Keycloak, which provides extended administrative user interface capabilities. The issue occurs because certain bulk role-removal endpoints fail to perform granular permission checks when deleting role mappings. This allows a delegated administrator with limited permissions to remove highly privileged roles from other users or groups, potentially disrupting administrative access control. | |
| Title | Keycloak-rest-admin-ui-ext: authorization bypass vulnerability in the admin-ui-ext bulk role-mapping-delete endpoints of keycloak | |
| First Time appeared |
Redhat
Redhat build Keycloak Redhat jbosseapxp |
|
| Weaknesses | CWE-425 | |
| CPEs | cpe:/a:redhat:build_keycloak: cpe:/a:redhat:jbosseapxp |
|
| Vendors & Products |
Redhat
Redhat build Keycloak Redhat jbosseapxp |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-06-11T18:50:30.698Z
Reserved: 2026-06-11T14:18:10.409Z
Link: CVE-2026-11986
Updated: 2026-06-11T18:49:48.522Z
Status : Received
Published: 2026-06-11T18:16:25.033
Modified: 2026-06-11T18:16:25.033
Link: CVE-2026-11986
No data.
OpenCVE Enrichment
Updated: 2026-06-11T20:30:28Z