A flaw was found in the admin REST API of Keycloak, a...
Moderate severity
Unreviewed
Published
Jul 17, 2026
to the GitHub Advisory Database
•
Updated Aug 31, 2026
Description
Published by the National Vulnerability Database
Jul 17, 2026
Published to the GitHub Advisory Database
Jul 17, 2026
Last updated
Aug 31, 2026
A flaw was found in the admin REST API of Keycloak, a solution for identity and access management. The issue occurs when a delegated administrator attempts to remove a child role from a composite role. Due to missing authorization checks, an attacker with limited administrative permissions can remove privileged roles they are not authorized to manage, leading to a loss of access for other users and administrators.
References