Junglewise Threat Intelligence

CVE-2026-11986: Keycloak authorization bypass in admin-ui-ext bulk role removal

CVE-2026-11986 · Severity: medium · CVSS 4.9 · Published 2026-06-11

Vendors: Keycloak, Maven, Red Hat.

Executive brief

Keycloak is an authentication and single sign-on service used to manage user access across applications. The admin interface extension contains a flaw where bulk operations to remove user and group roles skip important permission checks. A delegated administrator with partial permissions can exploit this to strip critical administrative roles from other administrators, disrupting access controls and potentially locking out legitimate admins.

Technical details

The vulnerability exists in the admin-ui-ext bulk role-mapping-delete endpoints (POST /admin/realms/{realm}/ui-ext/role-mapping-delete/users/{id} and POST /admin/realms/{realm}/ui-ext/role-mapping-delete/groups/{id}). The implementation performs only a container-level authorization check (requireMapRoles) but omits the per-role authorization check (requireMapRole) enforced by the standard Admin REST API. This is an authorization bypass (CWE-425) affecting the granular access control model. An authenticated attacker with high-level privileges (delegated administrator with manage-users permissions) can bypass intended restrictions to remove sensitive realm-management roles such as manage-realm, manage-clients, or realm-admin from other administrators—operations that would be correctly rejected with 403 Forbidden via the standard API. The vulnerability requires the attacker to have existing administrative credentials but allows escalation of privilege within the delegated scope. Patches are available in version 26.7.0 and later.

Affected products

  • Keycloak keycloak-rest-admin-ui-ext < 26.7.0

Timeline

  • 2026-06-11: disclosed
  • 2026-06-11: patched: Fixed in version 26.7.0

References