CVE-2026-16106: Keycloak-services: keycloak-services: incorrect authorization in admin role-composite deletion allows delegated admin to remove privileged child roles

Published Jul 17, 2026
·
Updated

A flaw was found in the admin REST API of Keycloak, a solution for identity and access management. The issue occurs when a delegated administrator attempts to remove a child role from a composite role. Due to missing authorization checks, an attacker with limited administrative permissions can remove privileged roles they are not authorized to manage, leading to a loss of access for other users and administrators.

Other sources

An incorrect authorization flaw was found in the Keycloak admin REST API endpoints responsible for removing child roles from composite roles. Specifically, the DELETE /admin/realms/{realm}/roles-by-id/{role-id}/composites and DELETE /admin/realms/{realm}/roles/{role-name}/composites endpoints only verify if the caller has manage permissions on the parent role container. They fail to enforce the per-child role check that is correctly implemented in the corresponding add operation. To exploit this, an attacker must have a delegated admin account with manage permissions on a parent role container (such as manage-realm or Fine-Grained Admin Permissions on a specific role container). No user interaction is required. A successful attack allows a delegated administrator to remove privileged child roles (like realm-admin) from existing composites. This results in stripping those roles from all users or groups assigned to the composite, effectively degrading the privileges of other administrators or disrupting realm-wide functionality by modifying default roles.

Red Hat

Affected Software

1 affected component
Keycloak Keycloak

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Compensating control

    Restrict access to the Keycloak admin REST API endpoints that allow role-composite deletion: DELETE /admin/realms/{realm}/roles-by-id/{role-id}/composites and DELETE /admin/realms/{realm}/roles/{role-name}/composites, allowing only trusted admins (limit delegated admin accounts so they do not have manage permissions on parent role containers they do not need, e.g., manage-realm or Fine-Grained Admin Permissions on specific role containers).

Event History

Jul 17, 2026
Data Sourced
via Red Hat·02:53 PM
DescriptionSeverityAffected Software
CVE Published
via MITRE·04:43 PM
Data Sourced
via MITRE·04:43 PM
DescriptionSeverity
Data Sourced
via NVD·05:17 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-16106?

The severity of CVE-2026-16106 is medium with a CVSS score of 4.9.

2

How do I fix CVE-2026-16106?

To fix CVE-2026-16106, ensure that appropriate authorization checks are implemented for role-composite deletions in Keycloak.

3

Who is affected by CVE-2026-16106?

CVE-2026-16106 affects Keycloak users, particularly those using the admin REST API with delegated administration.

4

What type of vulnerability is CVE-2026-16106?

CVE-2026-16106 is an authorization vulnerability allowing a delegated admin to improperly remove privileged child roles.

5

What impact does CVE-2026-16106 have on my system?

CVE-2026-16106 may allow unauthorized removal of critical roles, potentially leading to privilege escalation within Keycloak.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203