MEDIUMCVSS 6.5Vulnerability

CVE-2026-9796

A flaw was found in Keycloak. An authenticated administrator with the `manage-clients` role can exploit a Time-of-check to time-of-use (TOCTOU) vulnerability in the name-based admin role checks. This allows the attacker to escalate their privileges to `realm-admin` for all users within the realm, granting them extensive control over the system. The composite role relationship persists even after the attacker's own permissions are revoked and across system reboots.

Properties

severity
MEDIUM
cvss_severity
MEDIUM
cvss_score
6.5
epss_score
0.00379
retrieved_at
2026-09-25T06:03:36+00:00
last_source
FIRST EPSS
score
6.5
cve_id
CVE-2026-9796
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
signal_observed_at
2026-09-11T17:55:57+00:00
vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
published_at
2026-05-28T05:16:41.153
last_modified
2026-09-15T12:17:55.960
epss_percentile
0.29018

Related Entities (4)

ENRICHED_BY (1)

→[Source]FIRST EPSS

HAS_WEAKNESS (1)

→[Weakness]Time-of-check Time-of-use (TOCTOU) Race Condition

DESCRIBED_BY (1)

→[Source]NVD

AFFECTS_PRODUCT (1)

→[Product]

Explore deeper with Ninja Signal's threat intelligence graph