CVE-2026-16105: Authorization Bypass Through User-Controlled Key in Red Hat Red Hat Build of Keycloak
A flaw was found in the RoleContainerResource component of Keycloak. The issue occurs because certain name-based endpoints in the admin REST API do not properly enforce authorization checks when managing composite roles. This allows a delegated administrator with manage-realm permissions to remove essential child roles from built-in admin roles, potentially disrupting administrative functions within a realm.
AI Analysis
Technical Summary
CVE-2026-16105 is a vulnerability in the RoleContainerResource component of Red Hat Build of Keycloak where certain name-based endpoints in the admin REST API fail to properly enforce authorization checks when managing composite roles. This flaw allows a delegated administrator with manage-realm permissions to remove critical child roles from built-in admin roles, potentially disrupting administrative functions within a realm. The root cause is an incomplete fix for a previous issue, resulting in inconsistent authorization enforcement on these endpoints. The vulnerability has a CVSS v3.1 score of 4.9 (medium severity) with an attack vector of network, low attack complexity, and requiring high privileges. No known exploits are reported in the wild. Red Hat has not provided a patch or effective mitigation at this time.
Potential Impact
Successful exploitation allows an attacker with existing high-level delegated administrative privileges (manage-realm) to remove child roles from built-in admin roles. This leads to a loss of integrity in administrative configurations and can disrupt administrative functions within the affected realm. There is no impact on confidentiality or availability reported. The vulnerability does not allow privilege escalation beyond the existing delegated administrator permissions.
Mitigation Recommendations
Red Hat currently does not offer a patch or mitigation that meets their criteria for ease of use, applicability, or stability. Since exploitation requires high-level delegated administrative privileges, restricting and monitoring such privileges is advisable. Customers should follow Red Hat advisories and consider upgrading to fixed versions if and when they become available. For now, no direct mitigation or workaround is provided by Red Hat.
CVE-2026-16105: Authorization Bypass Through User-Controlled Key in Red Hat Red Hat Build of Keycloak
Description
A flaw was found in the RoleContainerResource component of Keycloak. The issue occurs because certain name-based endpoints in the admin REST API do not properly enforce authorization checks when managing composite roles. This allows a delegated administrator with manage-realm permissions to remove essential child roles from built-in admin roles, potentially disrupting administrative functions within a realm.
CVSS v3.1
Score 4.9medium
Affected software
Red Hat
Red Hat Build of Keycloak
Red Hat
Red Hat Data Grid 8
Red Hat
Red Hat JBoss Enterprise Application Platform Expansion Pack
Red Hat
Red Hat Single Sign-On 7
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-16105 is a vulnerability in the RoleContainerResource component of Red Hat Build of Keycloak where certain name-based endpoints in the admin REST API fail to properly enforce authorization checks when managing composite roles. This flaw allows a delegated administrator with manage-realm permissions to remove critical child roles from built-in admin roles, potentially disrupting administrative functions within a realm. The root cause is an incomplete fix for a previous issue, resulting in inconsistent authorization enforcement on these endpoints. The vulnerability has a CVSS v3.1 score of 4.9 (medium severity) with an attack vector of network, low attack complexity, and requiring high privileges. No known exploits are reported in the wild. Red Hat has not provided a patch or effective mitigation at this time.
Potential Impact
Successful exploitation allows an attacker with existing high-level delegated administrative privileges (manage-realm) to remove child roles from built-in admin roles. This leads to a loss of integrity in administrative configurations and can disrupt administrative functions within the affected realm. There is no impact on confidentiality or availability reported. The vulnerability does not allow privilege escalation beyond the existing delegated administrator permissions.
Mitigation Recommendations
Red Hat currently does not offer a patch or mitigation that meets their criteria for ease of use, applicability, or stability. Since exploitation requires high-level delegated administrative privileges, restricting and monitoring such privileges is advisable. Customers should follow Red Hat advisories and consider upgrading to fixed versions if and when they become available. For now, no direct mitigation or workaround is provided by Red Hat.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- redhat
- Date Reserved
- 2026-07-17T14:50:31.309Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-16105","vendor":"Red Hat"}]
Threat ID: 6a6c50cf9c2644c7f87f985d
Added to database: 07/31/2026, 07:37:51 UTC
Last enriched: 08/07/2026, 14:54:22 UTC
Last updated: 09/11/2026, 07:31:51 UTC
Views: 55
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.