Red Hat build of Keycloak 26.6 vulnerability

A flaw was found in the admin REST API of Keycloak, a solution for identity and access management. The issue occurs when a delegated administrator attempts to remove a child role from a composite role. Due to missing authorization checks, an attacker with limited administrative permissions can remove privileged roles they are not authorized to manage, leading to a loss of access for other users and administrators.

Published 17 Jul 2026Updated 16 Sep 20264 sources
CVSS 4.9

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.