Red Hat build of Keycloak 26.6 vulnerability

A flaw was found in the admin REST API of Keycloak, a solution for identity and access management. The issue occurs when a delegated administrator attempts to remove a child role from a composite role. Due to missing authorization checks, an attacker with limited administrative permissions can remove privileged roles they are not authorized to manage, leading to a loss of access for other users and administrators.

Published 17 Jul 2026Updated 16 Sep 20264 sources
CVSS 4.9

Source timeline

CVE record published by NVDView source ↗