Direct Request ('Forced Browsing') Affecting org.keycloak:keycloak-rest-admin-ui-ext package, versions [26.6.0,26.7.0)


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.3% (23rd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-ORGKEYCLOAK-17339779
  • published15 Jun 2026
  • disclosed11 Jun 2026
  • creditWesley "Alardiians" Colquitt

Introduced: 11 Jun 2026

CVE-2026-11986  (opens in a new tab)
CWE-425  (opens in a new tab)

How to fix?

Upgrade org.keycloak:keycloak-rest-admin-ui-ext to version 26.7.0 or higher.

Overview

Affected versions of this package are vulnerable to Direct Request ('Forced Browsing') due to missing granular authorization checks in the bulk role-mapping-delete endpoints (POST /admin/realms/{realm}/ui-ext/role-mapping-delete/users/{id} and POST /admin/realms/{realm}/ui-ext/role-mapping-delete/groups/{id}). An attacker can remove critical administrative roles from other users or groups by sending crafted requests to these endpoints after obtaining high-level administrative privileges.

CVSS Base Scores

version 4.0
version 3.1