<Vulnerability name="CVE-2026-11986">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Moderate</ThreatSeverity>
    <PublicDate>2026-06-11T14:17:32</PublicDate>
    <Bugzilla id="2487906" url="https://bugzilla.redhat.com/show_bug.cgi?id=2487906" xml:lang="en:us">
keycloak-rest-admin-ui-ext: Authorization Bypass vulnerability in the admin-ui-ext bulk role-mapping-delete endpoints of Keycloak
    </Bugzilla>
    <CVSS3 status="verified">
        <CVSS3BaseScore>4.9</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-425</CWE>
    <Details xml:lang="en:us" source="Mitre">
A flaw was found in the admin-ui-ext component of Keycloak, which provides extended administrative user interface capabilities. The issue occurs because certain bulk role-removal endpoints fail to perform granular permission checks when deleting role mappings. This allows a delegated administrator with limited permissions to remove highly privileged roles from other users or groups, potentially disrupting administrative access control.
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in the admin-ui-ext component of Keycloak, which provides extended administrative user interface capabilities. The issue occurs because certain bulk role-removal endpoints fail to perform granular permission checks when deleting role mappings. This allows a delegated administrator with limited permissions to remove highly privileged roles from other users or groups, potentially disrupting administrative access control.
    </Details>
    <Statement xml:lang="en:us">
The Red Hat Product Security team has assessed the severity of this vulnerability as Moderate, given that it requires the attacker to already possess high-level administrative privileges (delegated administrator) to be exploited. Successful exploitation allows an attacker to remove critical administrative roles from other users, leading to an unauthorized modification of access controls. The vulnerability's root cause is the omission of granular per-role authorization checks in the bulk deletion endpoints of the admin-ui-ext extension.
    </Statement>
    <Acknowledgement xml:lang="en:us">
Red Hat would like to thank Wesley "Alardiians" Colquitt (Byteshyft Studios) for reporting this issue.
    </Acknowledgement>
    <Mitigation xml:lang="en:us">
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
    </Mitigation>
    <AffectedRelease cpe="cpe:/a:redhat:build_keycloak:26.6::el9">
        <ProductName>Red Hat build of Keycloak 26.6</ProductName>
        <ReleaseDate>2026-08-05T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:50849">RHSA-2026:50849</Advisory>
        <Package name="rhbk/keycloak-operator-bundle">rhbk/keycloak-operator-bundle:26.6.5-1</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:build_keycloak:26.6::el9">
        <ProductName>Red Hat build of Keycloak 26.6</ProductName>
        <ReleaseDate>2026-08-05T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:50849">RHSA-2026:50849</Advisory>
        <Package name="rhbk/keycloak-rhel9">rhbk/keycloak-rhel9:26.6-11</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:build_keycloak:26.6::el9">
        <ProductName>Red Hat build of Keycloak 26.6</ProductName>
        <ReleaseDate>2026-08-05T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:50849">RHSA-2026:50849</Advisory>
        <Package name="rhbk/keycloak-rhel9-operator">rhbk/keycloak-rhel9-operator:26.6-11</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:build_keycloak:26.6::el9">
        <ProductName>Red Hat build of Keycloak 26.6.5</ProductName>
        <ReleaseDate>2026-08-05T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:50848">RHSA-2026:50848</Advisory>
        <Package name="keycloak-rest-admin-ui-ext">keycloak-rest-admin-ui-ext</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:build_keycloak:26.6::el9">
        <ProductName>Red Hat build of Keycloak 26.6.5</ProductName>
        <ReleaseDate>2026-08-05T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:50848">RHSA-2026:50848</Advisory>
        <Package name="rhbk/keycloak-rhel9">rhbk/keycloak-rhel9</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:build_keycloak:26.6::el9">
        <ProductName>Red Hat build of Keycloak 26.6.5</ProductName>
        <ReleaseDate>2026-08-05T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:50848">RHSA-2026:50848</Advisory>
        <Package name="rhbk-openshift-rhel9/rhbk-openshift-rhel9">rhbk-openshift-rhel9/rhbk-openshift-rhel9</Package>
    </AffectedRelease>
    <PackageState cpe="cpe:/a:redhat:jbosseapxp">
        <ProductName>Red Hat JBoss Enterprise Application Platform Expansion Pack</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>keycloak-rest-admin-ui-ext</PackageName>
    </PackageState>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-11986
https://nvd.nist.gov/vuln/detail/CVE-2026-11986
    </References>
</Vulnerability>