By weakness (CWE)

CWE-425: related vulnerabilities

CVEs classified under CWE-425. Understanding the weakness class helps prioritize systemic fixes over one-off patches.

1 published vulnerability

  • CVE-2026-11986MEDIUM 4.9

    Keycloak's admin-ui-ext component has a permission-checking flaw that allows limited administrators to strip high-privilege roles from other users or administrators. An attacker with delegated admin rights can exploit bulk role-removal endpoints to bypass intended access controls, potentially locking out legitimate administrators or escalating their own influence within the system.