SEPTEMBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-16106

MEDIUM · CVSS 4.9 EPSS 0.19%

Source: NVD + CISA KEV + EPSS · Published 2026-07-17 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

A vulnerability exists in the admin REST API of Keycloak, allowing delegated administrators to remove child roles from composite roles without proper authorization checks. This flaw can be exploited by attackers with limited administrative permissions to revoke access from other users and administrators, potentially disrupting access control and compromising security. Organizations using Keycloak for identity and access management should prioritize addressing this issue to safeguard their role management and access integrity.

CVE
CVE-2026-16106
Severity
MEDIUM
CVSS
4.9
EPSS
0.19%

Original NVD Description

A flaw was found in the admin REST API of Keycloak, a solution for identity and access management. The issue occurs when a delegated administrator attempts to remove a child role from a composite role. Due to missing authorization checks, an attacker with limited administrative permissions can remove privileged roles they are not authorized to manage, leading to a loss of access for other users and administrators.

Related CVEs

Other vulnerabilities affecting the same vendor(s)