MEDIUMVulnerability

CVE-2026-9796

A flaw was found in Keycloak. An authenticated administrator with the `manage-clients` role can exploit a Time-of-check to time-of-use (TOCTOU) vulnerability in the name-based admin role checks. This allows the attacker to escalate their privileges to `realm-admin` for all users within the realm, granting them extensive control over the system. The composite role relationship persists even after the attacker's own permissions are revoked and across system reboots.

Properties

severity
MEDIUM
score
6.5
cve_id
CVE-2026-9796
vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
published_at
2026-05-28T05:16:41.153
last_modified
2026-08-11T12:17:44.393

Related Entities (3)

HAS_WEAKNESS (1)

[Weakness]Time-of-check Time-of-use (TOCTOU) Race Condition

DESCRIBED_BY (1)

[Source]NVD

AFFECTS_PRODUCT (1)

[Product]

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-9796 — Ninja Signal Threat Intelligence | Ninja Signal