Junglewise Threat Intelligence

CVE-2026-16106: Keycloak missing authorization in admin REST API role management

CVE-2026-16106 · Severity: medium · CVSS 4.9 · Published 2026-07-17

Technologies: Red Hat build of Keycloak, Red Hat build of Keycloak. Vendors: Red Hat.

Executive brief

A security flaw was found in Keycloak, an identity and access management system used to secure applications and manage user credentials. A user with limited administrative access can remove high-level security roles from the system that they should not be allowed to modify. This could allow a malicious insider to strip other administrators of their access or disrupt critical security configurations across the organization.

Technical details

A missing authorization check exists in the Keycloak admin REST API endpoints responsible for removing child roles from composite roles (specifically the DELETE /admin/realms/{realm}/roles-by-id/{role-id}/composites and DELETE /admin/realms/{realm}/roles/{role-name}/composites endpoints). While the API verifies if the caller has 'manage' permissions on the parent role container, it fails to perform per-child role authorization checks. An attacker with delegated administrative permissions can exploit this to remove privileged child roles (such as realm-admin) from existing composites. This results in the removal of those roles from all users or groups assigned to the composite, leading to unauthorized privilege modification or denial of service for other administrators.

Affected products

  • Red Hat Red Hat Build of Keycloak unspecified

Timeline

  • 2026-07-17: disclosed
  • 2026-07-17: advisory

References

Related threats