Missing Authorization in Keycloak - CVE-2026-16106
Published: July 17, 2026 / Updated: September 5, 2026
Vulnerability details
The vulnerability allows a remote user to remove privileged roles they are not authorized to manage.
The vulnerability exists due to missing authorization checks in the admin REST API when removing a child role from a composite role. A remote privileged user can remove a child role from a composite role to remove privileged roles they are not authorized to manage.