What is CVE-2026-16105?
An authorization flaw was found in the RoleContainerResource component of Keycloak, where certain name-based endpoints in the admin REST API lack proper permission checks for managing composite roles. This could allow a delegated administrator with manage-realm permissions to remove roles they shouldn't. Organizations should review their Keycloak instances and apply the necessary patches immediately.
Azərbaycanca: Keycloak-in RoleContainerResource komponentində yetkiləndirmə zəifliyi aşkarlanıb. Admin REST API-də ad-əsaslı endpoint-lər kompozit rolları idarə edərkən düzgün yoxlama aparmır, bu da idarəetmə icazəsi olan bir adminə əlavə rolları silməyə imkan verir. Təşkilatlar dərhal Keycloak instansiyalarını yoxlamalı və müvafiq yeniləmələri tətbiq etməlidir.
Related CVEs
link basis: same weakness class CWE-863
FAQ2
Who can exploit the CVE-2026-16105 vulnerability in Keycloak?
A delegated administrator with manage-realm permissions in the admin REST API, but without the authority to remove certain roles, can exploit this flaw.
Which Keycloak component is affected by CVE-2026-16105?
The vulnerability is in the RoleContainerResource component of Keycloak, where name-based endpoints fail to properly check permissions when managing composite roles.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.