Metrics
Affected Vendors & Products
Tue, 18 Aug 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:build_keycloak:26.6 cpe:/a:redhat:build_keycloak:26.6::el9 |
|
| References |
|
Wed, 03 Jun 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat build Of Keycloak
|
|
| CPEs | cpe:2.3:a:redhat:build_of_keycloak:-:*:*:*:-:*:*:* | |
| Vendors & Products |
Redhat build Of Keycloak
|
Sat, 30 May 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat keycloak
|
|
| Vendors & Products |
Redhat keycloak
|
Thu, 28 May 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 28 May 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Thu, 28 May 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in Keycloak. An authenticated administrator with the `manage-clients` role can exploit a Time-of-check to time-of-use (TOCTOU) vulnerability in the name-based admin role checks. This allows the attacker to escalate their privileges to `realm-admin` for all users within the realm, granting them extensive control over the system. The composite role relationship persists even after the attacker's own permissions are revoked and across system reboots. | |
| Title | Keycloak: keycloak: privilege escalation via time-of-check to time-of-use (toctou) vulnerability | |
| First Time appeared |
Redhat
Redhat build Keycloak |
|
| Weaknesses | CWE-367 | |
| CPEs | cpe:/a:redhat:build_keycloak: | |
| Vendors & Products |
Redhat
Redhat build Keycloak |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-08-19T03:21:30.423Z
Reserved: 2026-05-28T03:31:58.205Z
Link: CVE-2026-9796
Updated: 2026-05-28T12:16:54.515Z
Status : Modified
Published: 2026-05-28T05:16:41.153
Modified: 2026-08-19T04:17:43.890
Link: CVE-2026-9796
OpenCVE Enrichment
Updated: 2026-05-30T21:19:24Z