PatchSiren cyber security CVE debrief
CVE-2026-16105 Red Hat CVE debrief
A flaw was found in the RoleContainerResource component of Keycloak. The issue occurs because certain name-based endpoints in the admin REST API do not properly enforce authorization checks when managing composite roles. This allows a delegated administrator with manage-realm permissions to remove essential child roles from built-in admin roles, potentially disrupting administrative functions within a realm.
- Vendor
- Red Hat
- Product
- Red Hat Build of Keycloak
- CVSS
- MEDIUM 4.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-31
- Original CVE updated
- 2026-07-31
- Advisory published
- 2026-07-31
- Advisory updated
- 2026-07-31
Who should care
Administrators and security teams managing Keycloak instances, especially those with delegated administrators and manage-realm permissions, should review compensating controls for exposed systems while remediation is scheduled and verified. They should also monitor for unusual role modifications within the admin REST API and track exceptions, retest remediated assets, and close the item only after evidence is documented. Additionally, they should plan vendor-supported updates or mitigations through normal change control where exposure is confirmed and check relevant monitoring, detection, and logs for exposed assets that need extra review. Affected operator, platform, vulnerability-management, and security-team impact should be considered when assessing who should care about this vulnerability. For example, security teams should verify Keycloak instance for RoleContainerResource component usage and review delegated administrator permissions and manage-realm access. They should also consider compensating controls for exposed systems while remediation is scheduled and verified, and monitor for unusual role modifications within the admin REST API. Furthermore, they should track exceptions, retest remediated assets, and close the item only after evidence is documented. Lastly, they should plan vendor-supported updates or mitigations through normal change control where exposure is confirmed and check relevant monitoring, detection, and logs for exposed assets that need extra review. This should be done by confirming whether affected product deployments exist in managed environments and assigning an owner for follow-up. The supplied official advisory or CVE record should be reviewed to validate affected scope, severity, and vendor guidance. Compensating controls should be reviewed for exposed systems while remediation is scheduled and verified. Monitoring, detection, and logs should be checked for exposed assets that need extra review. Exceptions should be tracked, remediated assets should be retested, and the item should be closed only after evidence is documented. Vendor-supported updates or mitigations should be planned through normal change control where exposure
Technical summary
The RoleContainerResource component of Keycloak contains a flaw due to inadequate authorization checks in certain name-based endpoints of the admin REST API. This vulnerability allows a delegated administrator with manage-realm permissions to remove essential child roles from built-in admin roles, potentially disrupting administrative functions within a realm. Affected product context includes Keycloak instances with RoleContainerResource component usage. Defensive impact involves verifying Keycloak instance for RoleContainerResource component usage and reviewing delegated administrator permissions and manage-realm access.
Defensive priority
Medium priority due to potential disruption of administrative functions
Recommended defensive actions
- Verify Keycloak instance for RoleContainerResource component usage
- Review delegated administrator permissions and manage-realm access
- Monitor for unusual role modifications within the admin REST API
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
Evidence notes
Evidence from official CVE and NVD sources indicate a medium severity flaw in Keycloak's RoleContainerResource component. Details are limited, and further verification is recommended. Affected product deployments should be confirmed in managed environments, and owners assigned for follow-up. The official advisory or CVE record should be reviewed to validate affected scope, severity, and vendor guidance.
Official resources
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-31T08:16:25.940Z and has not been modified since then.