GHSA-pq65-77rc-7r8c
MODERATECVE-2026-9796A flaw was found in Keycloak. An authenticated administrator with the manage-clients role can exploit a Time-of-check to time-of-use (TOCTOU) vulnerability in the name-based admin role checks. This allows the attacker to escalate their privileges to realm-admin for all users within the realm, granting them extensive control over the system. The composite role relationship persists even after the a
- Affected
- < 26.6.4
- Fixed in
- 26.6.4
- Weakness
- CWE-367
- Published
- 2026-05-28
- Source
- github
GHSANVDMITREreferencereferencereferencereferencereferencereferencereference