MEDIUM 4.9
GHSA-6w3v-mcfh-m3q7
Keycloak Admin UI REST Extensions: bulk role-removal endpoints fail to perform granular permission checks
Quick fix
GHSA-6w3v-mcfh-m3q7 — org.keycloak:keycloak-rest-admin-ui-ext: upgrade to the fixed version with the command below.
# pom.xml: bump <version>26.7.0</version> for org.keycloak:keycloak-rest-admin-ui-ext Details
A flaw was found in the admin-ui-ext component of Keycloak, which provides extended administrative user interface capabilities. The issue occurs because certain bulk role-removal endpoints fail to perform granular permission checks when deleting role mappings. This allows a delegated administrator with limited permissions to remove highly privileged roles from other users or groups, potentially disrupting administrative access control.
Are you affected?
Enter the version of the package you're using.
Affected packages
Maven / org.keycloak:keycloak-rest-admin-ui-ext
Introduced in:
0 Fixed in: 26.7.0 Fix
# pom.xml: bump <version>26.7.0</version> for org.keycloak:keycloak-rest-admin-ui-ext References
- https://nvd.nist.gov/vuln/detail/CVE-2026-11986 [ADVISORY]
- https://github.com/keycloak/keycloak/issues/49766 [WEB]
- https://github.com/keycloak/keycloak/pull/49826 [WEB]
- https://github.com/keycloak/keycloak/commit/f3831f01fd4abceb47e9675ab5f4c17268ba9e9d [WEB]
- https://access.redhat.com/errata/RHSA-2026:50848 [WEB]
- https://access.redhat.com/errata/RHSA-2026:50849 [WEB]
- https://access.redhat.com/security/cve/CVE-2026-11986 [WEB]
- https://bugzilla.redhat.com/show_bug.cgi?id=2487906 [WEB]
- https://github.com/keycloak/keycloak [PACKAGE]
- https://github.com/keycloak/keycloak/releases/tag/26.7.0 [WEB]