By weakness (CWE)
CWE-425: related vulnerabilities
CVEs classified under CWE-425. Understanding the weakness class helps prioritize systemic fixes over one-off patches.
1 published vulnerability
- CVE-2026-11986MEDIUM 4.9
Keycloak's admin-ui-ext component has a permission-checking flaw that allows limited administrators to strip high-privilege roles from other users or administrators. An attacker with delegated admin rights can exploit bulk role-removal endpoints to bypass intended access controls, potentially locking out legitimate administrators or escalating their own influence within the system.