CyberSec.Space Logo
返回 CVE 浏览器

CVE-2026-11986

MEDIUM
4.9
CVSS Severity Score
EPSS Score0.1070%
EPSS Percentile35.11th
Published2026年6月11日
Last Modified2026年6月11日

Vulnerability Description

A flaw was found in the admin-ui-ext component of Keycloak, which provides extended administrative user interface capabilities. The issue occurs because certain bulk role-removal endpoints fail to perform granular permission checks when deleting role mappings. This allows a delegated administrator with limited permissions to remove highly privileged roles from other users or groups, potentially disrupting administrative access control.

Affected Platforms (CPE)

No CPE configurations currently published for this record.

References & Advisories

相关漏洞威胁