CVE-2026-16105
Received Received - Intake

Keycloak RoleContainerResource Authorization Bypass Vulnerability

Vulnerability report for CVE-2026-16105, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-31

Last updated on: 2026-07-31

Assigner: Red Hat, Inc.

Description

A flaw was found in the RoleContainerResource component of Keycloak. The issue occurs because certain name-based endpoints in the admin REST API do not properly enforce authorization checks when managing composite roles. This allows a delegated administrator with manage-realm permissions to remove essential child roles from built-in admin roles, potentially disrupting administrative functions within a realm.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-31
Last Modified
2026-07-31
Generated
2026-07-31
AI Q&A
2026-07-31
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
keycloak rolecontainerresource *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in Keycloak's RoleContainerResource component. It involves missing authorization checks in the admin REST API's name-based endpoints for managing composite roles. A delegated admin with manage-realm permissions can exploit this to remove critical child roles from built-in admin roles, disrupting administrative functions.

Detection Guidance

To detect this vulnerability, monitor Keycloak admin REST API logs for unauthorized DELETE requests to name-based composite endpoints like /admin/realms/{realm}/roles/{role-name}/composites. Check for unusual removal of child roles from built-in admin roles such as manage-users, impersonation, or manage-clients.

Impact Analysis

An attacker with manage-realm permissions could remove essential roles like manage-users or impersonation from admin accounts. This would degrade other administrators' permissions, potentially locking them out of critical functions or enabling unauthorized access if combined with other flaws.

Compliance Impact

This vulnerability could indirectly impact compliance with GDPR or HIPAA by allowing unauthorized privilege reduction for administrators. If an attacker removes critical roles like manage-users or impersonation from built-in admin roles, it may disrupt legitimate administrative functions, potentially leading to unauthorized access or data exposure. However, the direct impact depends on the specific deployment and role assignments.

Mitigation Strategies

Apply the latest Keycloak security patches immediately. Review and restrict delegated administrator permissions to ensure they cannot modify built-in admin roles. Temporarily disable name-based composite endpoints if patches are not available.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-16105. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart