CyberRota Analysis
AI-GeneratedA vulnerability exists in the admin REST API of Keycloak, allowing delegated administrators to remove child roles from composite roles without proper authorization checks. This flaw can be exploited by attackers with limited administrative permissions to revoke access from other users and administrators, potentially disrupting access control and compromising security. Organizations using Keycloak for identity and access management should prioritize addressing this issue to safeguard their role management and access integrity.
Original NVD Description
A flaw was found in the admin REST API of Keycloak, a solution for identity and access management. The issue occurs when a delegated administrator attempts to remove a child role from a composite role. Due to missing authorization checks, an attacker with limited administrative permissions can remove privileged roles they are not authorized to manage, leading to a loss of access for other users and administrators.
Related CVEs
Other vulnerabilities affecting the same vendor(s)