VDB
KO
MEDIUM 4.9

GHSA-6w3v-mcfh-m3q7

Keycloak Admin UI REST Extensions: bulk role-removal endpoints fail to perform granular permission checks

Quick fix

GHSA-6w3v-mcfh-m3q7 — org.keycloak:keycloak-rest-admin-ui-ext: upgrade to the fixed version with the command below.

# pom.xml: bump <version>26.7.0</version> for org.keycloak:keycloak-rest-admin-ui-ext

Details

A flaw was found in the admin-ui-ext component of Keycloak, which provides extended administrative user interface capabilities. The issue occurs because certain bulk role-removal endpoints fail to perform granular permission checks when deleting role mappings. This allows a delegated administrator with limited permissions to remove highly privileged roles from other users or groups, potentially disrupting administrative access control.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven / org.keycloak:keycloak-rest-admin-ui-ext
Introduced in: 0 Fixed in: 26.7.0
Fix # pom.xml: bump <version>26.7.0</version> for org.keycloak:keycloak-rest-admin-ui-ext

References