Direct Request ('Forced Browsing') in Red Hat build of Keycloak - CVE-2026-11986
Published: September 11, 2026
Vulnerability details
The vulnerability allows a remote user to remove highly privileged roles from other users or groups.
The vulnerability exists due to missing granular authorization checks in the admin-ui-ext bulk role-mapping-delete endpoints when deleting role mappings. A remote privileged user can use the bulk role-removal endpoints to remove highly privileged roles from other users or groups.