CVE-2026-11577
Last modified
This CVE is reserved or rejected; no details have been published by NVD.
Description
Rejected reason: The reported behavior does not constitute a privilege escalation. Exploitation requires the attacker to already possess the manage-realm administrative role within the realm-management client. By design, the manage-realm role is intended to be equivalent in administrative authority to realm-admin. A user with manage-realm already has full administrative control over the realm. Therefore, importing users with realm-admin role mappings through POST /admin/realms/{realm}/partialImport does not grant any additional privileges beyond those already held by the administrator and does not represent a security vulnerability.
Metrics
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat Build of Keycloak | All versions |
| Red Hat | Red Hat Single Sign-On 7 | All versions |
Timeline
- Published
- Last Modified
- Status
- Rejected
Related CVEs from 2026
- CVE-2026-11570The User Submitted Posts WordPress plugin before 20260608 d…4.2
- CVE-2026-11571The Everest Forms WordPress plugin before 3.5.0 does not re…7.5
- CVE-2026-11572Versions of the package degit before 2.8.6, from 3.0.0 and b…8.8
- CVE-2026-11573Uncontrolled recursion (CWE-674) in the QDomDocument/QDomNod…7.1
- CVE-2026-11575The PhonePe Payment Solutions WordPress plugin before 3.1.0 …7.5
- CVE-2026-11576The security fix for CVE-2025-0728 in eclipse-threadx NetX D…7.5
- CVE-2026-11578The Fluent Forms WordPress plugin before 6.2.5 does not pro…2.7
- CVE-2026-11579The Kali Forms — Contact Form & Drag-and-Drop Builder WordPr…5.3
- CVE-2026-1158A security flaw has been discovered in Totolink LR350 9.3.5u…8.8
- CVE-2026-11580The Kali Forms — Contact Form & Drag-and-Drop Builder WordPr…5.5
- CVE-2026-11581The Kali Forms — Contact Form & Drag-and-Drop Builder WordPr…5.9
- CVE-2026-11582A flaw has been found in CodeAstro Student Attendance Manage…7.3
Are you affected by CVE-2026-11577?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
