VYPR
Unrated severityNVD Advisory· Published Jul 31, 2026· Updated Jul 31, 2026

Keycloak-services: keycloak-services: missing per-role authorization on rolecontainerresource composite endpoints

CVE-2026-16105

Description

A flaw was found in the RoleContainerResource component of Keycloak. The issue occurs because certain name-based endpoints in the admin REST API do not properly enforce authorization checks when managing composite roles. This allows a delegated administrator with manage-realm permissions to remove essential child roles from built-in admin roles, potentially disrupting administrative functions within a realm.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

1

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.