4.9 CVE-2026-11986

Enriched by CISA
 

A flaw was found in the admin-ui-ext component of Keycloak, which provides extended administrative user interface capabilities. The issue occurs because certain bulk role-removal endpoints fail to perform granular permission checks when deleting role mappings. This allows a delegated administrator with limited permissions to remove highly privileged roles from other users or groups, potentially disrupting administrative access control.
https://nvd.nist.gov/vuln/detail/CVE-2026-11986

Categories

CWE-425 : Direct Request ('Forced Browsing')
The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files. The "forced browsing" term could be misinterpreted to include weaknesses such as CSRF or XSS, so its use is discouraged. Apply appropriate access control authorizations for each access to all restricted URLs, scripts or files. Consider using MVC based frameworks such as Struts. Access-control setting in web-based document collaboration tool is not properly implemented by the code, which prevents listing hidden directories but does not prevent direct requests to files in those directories. Bypass authentication via direct request. Infinite loop or infoleak triggered by direct requests. Bypass auth/auth via direct request. Direct request leads to infoleak by error. Direct request leads to infoleak by error. Direct request leads to infoleak by error. Authentication bypass via direct request. Authentication bypass via direct request. Authorization bypass using direct request. Access privileged functionality using direct request. Upload arbitrary files via direct request.

References


 

AFFECTED (from MITRE)


Vendor Product Versions
Red Hat Red Hat Build of Keycloak
    Red Hat Red Hat Build of Keycloak
      Red Hat Red Hat Build of Keycloak
        Red Hat Red Hat JBoss Enterprise Application Platform Expansion Pack
          © 2022 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.

          CPE

          cpe start end


          REMEDIATION




          EXPLOITS


          Exploit-db.com

          id description date
          No known exploits

          POC Github

          Url
          No known exploits

          Other Nist (github, ...)

          Url
          No known exploits


          CAPEC


          Common Attack Pattern Enumerations and Classifications

          id description severity
          127 Directory Indexing
          Medium
          143 Detect Unpublicized Web Pages
          Low
          144 Detect Unpublicized Web Services
          Low
          668 Key Negotiation of Bluetooth Attack (KNOB)
          High
          87 Forceful Browsing
          High


          MITRE


          Techniques

          id description
          T1083 File and Directory Discovery
          T1565.002 Data Manipulation: Transmitted Data Manipulation
          © 2022 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.

          Mitigations

          id description
          M1041 Encrypt all important data flows to reduce the impact of tailored modifications on data in transit.
          © 2022 The MITRE Corporation. Esta obra se reproduce y distribuye con el permiso de The MITRE Corporation.