NONE · 0

CVE-2026-11577

Rejected reason: The reported behavior does not constitute a privilege escalation. Exploitation requires the attacker to already possess the manage-realm administrative role within the realm-managemen...

Vulnerability Description

Rejected reason: The reported behavior does not constitute a privilege escalation. Exploitation requires the attacker to already possess the manage-realm administrative role within the realm-management client. By design, the manage-realm role is intended to be equivalent in administrative authority to realm-admin. A user with manage-realm already has full administrative control over the realm. Therefore, importing users with realm-admin role mappings through POST /admin/realms/{realm}/partialImport does not grant any additional privileges beyond those already held by the administrator and does not represent a security vulnerability.

FAQ

What is CVE-2026-11577?

CVE-2026-11577 is a documented vulnerability. Rejected reason: The reported behavior does not constitute a privilege escalation. Exploitation requires the attacker to already possess the manage-realm administrative role within the realm-managemen...

How severe is CVE-2026-11577?

CVSS scoring is not yet available for CVE-2026-11577. Check NVD for updates.

Is there a patch for CVE-2026-11577?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.