CVE-2026-9796
A flaw was found in Keycloak. An authenticated administrator with the `manage-clients` role can exploit a Time-of-check to time-of-use (TOCTOU) vulnerability in the name-based admin role checks. This allows the attacker to escalate their privileges to `realm-admin` for all users within the realm, granting them extensive control over the system. The composite role relationship persists even after the attacker's own permissions are revoked and across system reboots.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.5
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
- EPSS probability
- 0.22%
- CWE
- CWE-367
- Published
- 2026-05-28
- Last modified
- 2026-09-15
Affected products
- Red Hat Red Hat build of Keycloak 26.6
- Red Hat Red Hat build of Keycloak 26.6
Weakness type
Related vulnerabilities
- CVE-2026-87433 — Race condition in FileAPI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the rend
- CVE-2026-79155 — Race condition in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the r
- CVE-2026-79071 — Race condition in GPU in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer
- CVE-2026-87554 — Race condition in Chromoting in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to execute a
- CVE-2026-87457 — Race condition in Updater in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to execute arbi
- CVE-2026-79263 — Race condition in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code
- CVE-2026-79057 — Race condition in Start in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker leveraging social
- CVE-2026-65183 — Apache Tomcat: TOCTOU when setting specific permissions for Unix Domain Sockets