Project Subscriptions
No advisories yet.
Solution
No solution given by the vendor.
Workaround
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Thu, 11 Jun 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 11 Jun 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in the admin-ui-ext component of Keycloak, which provides extended administrative user interface capabilities. The issue occurs because certain bulk role-removal endpoints fail to perform granular permission checks when deleting role mappings. This allows a delegated administrator with limited permissions to remove highly privileged roles from other users or groups, potentially disrupting administrative access control. | |
| Title | Keycloak-rest-admin-ui-ext: authorization bypass vulnerability in the admin-ui-ext bulk role-mapping-delete endpoints of keycloak | |
| First Time appeared |
Redhat
Redhat build Keycloak Redhat jbosseapxp |
|
| Weaknesses | CWE-425 | |
| CPEs | cpe:/a:redhat:build_keycloak: cpe:/a:redhat:jbosseapxp |
|
| Vendors & Products |
Redhat
Redhat build Keycloak Redhat jbosseapxp |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-06-11T18:50:30.698Z
Reserved: 2026-06-11T14:18:10.409Z
Link: CVE-2026-11986
Updated: 2026-06-11T18:49:48.522Z
Status : Awaiting Analysis
Published: 2026-06-11T18:16:25.033
Modified: 2026-06-11T20:56:29.653
Link: CVE-2026-11986
No data.
OpenCVE Enrichment
Updated: 2026-06-11T20:30:28Z