Keycloak Admin UI REST Extensions: bulk role-removal endpoints fail to perform granular permission checks
Moderate severity
GitHub Reviewed
Published
Jun 11, 2026
to the GitHub Advisory Database
•
Updated Aug 19, 2026
Package
Affected versions
< 26.7.0
Patched versions
26.7.0
Description
Published by the National Vulnerability Database
Jun 11, 2026
Published to the GitHub Advisory Database
Jun 11, 2026
Reviewed
Aug 19, 2026
Last updated
Aug 19, 2026
A flaw was found in the admin-ui-ext component of Keycloak, which provides extended administrative user interface capabilities. The issue occurs because certain bulk role-removal endpoints fail to perform granular permission checks when deleting role mappings. This allows a delegated administrator with limited permissions to remove highly privileged roles from other users or groups, potentially disrupting administrative access control.
References