A flaw was found in Keycloak. An authenticated administrator with the `manage-clients` role can exploit a Time-of-check to time-of-use (TOCTOU) vulnerability in the name-based admin role checks. This allows the attacker to escalate their privileges to `realm-admin` for all users within the realm, granting them extensive control over the system. The composite role relationship persists even after the attacker's own permissions are revoked and across system reboots.
History

Thu, 28 May 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Thu, 28 May 2026 04:45:00 +0000

Type Values Removed Values Added
Description A flaw was found in Keycloak. An authenticated administrator with the `manage-clients` role can exploit a Time-of-check to time-of-use (TOCTOU) vulnerability in the name-based admin role checks. This allows the attacker to escalate their privileges to `realm-admin` for all users within the realm, granting them extensive control over the system. The composite role relationship persists even after the attacker's own permissions are revoked and across system reboots.
Title Keycloak: keycloak: privilege escalation via time-of-check to time-of-use (toctou) vulnerability
First Time appeared Redhat
Redhat build Keycloak
Weaknesses CWE-367
CPEs cpe:/a:redhat:build_keycloak:
Vendors & Products Redhat
Redhat build Keycloak
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2026-05-28T04:27:08.794Z

Updated: 2026-05-28T12:16:58.840Z

Reserved: 2026-05-28T03:31:58.205Z

Link: CVE-2026-9796

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-05-28T05:16:41.153

Modified: 2026-05-28T05:16:41.153

Link: CVE-2026-9796

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-05-28T03:32:50Z

Links: CVE-2026-9796 - Bugzilla