CyberSec.Space Logo
Back to CVE Browser

CVE-2026-11986

MEDIUM
4.9
CVSS Severity Score
EPSS Score0.1070%
EPSS Percentile35.11th
PublishedJun 11, 2026
Last ModifiedJun 11, 2026

Vulnerability Description

A flaw was found in the admin-ui-ext component of Keycloak, which provides extended administrative user interface capabilities. The issue occurs because certain bulk role-removal endpoints fail to perform granular permission checks when deleting role mappings. This allows a delegated administrator with limited permissions to remove highly privileged roles from other users or groups, potentially disrupting administrative access control.

Affected Platforms (CPE)

No CPE configurations currently published for this record.

References & Advisories

Related Vulnerabilities