Time-of-check Time-of-use (TOCTOU) Race Condition in Red Hat build of Keycloak - CVE-2026-9796
Published: September 11, 2026
Vulnerability details
The vulnerability allows a remote user to escalate privileges to realm-admin for all users within the realm.
The vulnerability exists due to a time-of-check to time-of-use race condition in name-based admin role checks when processing administrative role checks. A remote privileged user can exploit the race condition to escalate privileges to realm-admin for all users within the realm.
Exploitation requires the manage-clients role. The resulting composite role relationship persists after the user\'s permissions are revoked and across system reboots.