CVE-2026-16105
Keycloak-services: keycloak-services: missing per-role authorization on rolecontainerresource composite endpoints
Record summary
CVE-2026-16105 has a selected CVSS score of 4.9 (medium).
Description
A flaw was found in the RoleContainerResource component of Keycloak. The issue occurs because certain name-based endpoints in the admin REST API do not properly enforce authorization checks when managing composite roles. This allows a delegated administrator with manage-realm permissions to remove essential child roles from built-in admin roles, potentially disrupting administrative functions within a realm.
Exploitation context
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 31, 2026 · Source: CVE List
Affected products and versions
6| Product | Source | Version range | Status |
|---|---|---|---|
Default status: affected | CVE List | Version data not supplied | |
Red Hat Build of KeycloakBrowse Red Hat / Red Hat Build of Keycloakrhbk-keycloak-rhel9/rhbk-keycloak-rhel9Default status: affected | CVE List | Version data not supplied | |
Red Hat Build of KeycloakBrowse Red Hat / Red Hat Build of Keycloakrhbk-openshift-rhel9/rhbk-openshift-rhel9Default status: affected | CVE List | Version data not supplied | |
Default status: unaffected | CVE List | Version data not supplied | |
Red Hat JBoss Enterprise Application Platform Expansion PackBrowse Red Hat / Red Hat JBoss Enterprise Application Platform Expansion Packkeycloak-servicesDefault status: unaffected | CVE List | Version data not supplied | |
Default status: unaffected | CVE List | Version data not supplied | |