CVE-2026-11577

UnknownEPSS 0.33%

Last modified

This CVE is reserved or rejected; no details have been published by NVD.

Description

Rejected reason: The reported behavior does not constitute a privilege escalation. Exploitation requires the attacker to already possess the manage-realm administrative role within the realm-management client. By design, the manage-realm role is intended to be equivalent in administrative authority to realm-admin. A user with manage-realm already has full administrative control over the realm. Therefore, importing users with realm-admin role mappings through POST /admin/realms/{realm}/partialImport does not grant any additional privileges beyond those already held by the administrator and does not represent a security vulnerability.

Metrics

EPSS Probability
0.33%

24.8th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
Red HatRed Hat Build of KeycloakAll versions
Red HatRed Hat Single Sign-On 7All versions

Timeline

Published
Last Modified
Status
Rejected

Related CVEs from 2026

Are you affected by CVE-2026-11577?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST