Vulnerability Description
A flaw was found in the admin-ui-ext component of Keycloak, which provides extended administrative user interface capabilities. The issue occurs because certain bulk role-removal endpoints fail to perform granular permission checks when deleting role mappings. This allows a delegated administrator with limited permissions to remove highly privileged roles from other users or groups, potentially disrupting administrative access control.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Build Of Keycloak | >= 26.6, < 26.6.5 |
Related Weaknesses (CWE)
References
- https://access.redhat.com/errata/RHSA-2026:50848Vendor Advisory
- https://access.redhat.com/errata/RHSA-2026:50849Vendor Advisory
- https://access.redhat.com/security/cve/CVE-2026-11986Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2487906Issue TrackingVendor Advisory
FAQ
What is CVE-2026-11986?
CVE-2026-11986 is a vulnerability with a CVSS score of 4.9 (MEDIUM). A flaw was found in the admin-ui-ext component of Keycloak, which provides extended administrative user interface capabilities. The issue occurs because certain bulk role-removal endpoints fail to per...
How severe is CVE-2026-11986?
CVE-2026-11986 has been rated MEDIUM with a CVSS base score of 4.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-11986?
Check the references section above for vendor advisories and patch information. Affected products include: Redhat Build Of Keycloak.