Echo: org.keycloak:keycloak-rest-admin-ui-ext: security update to 26.7.0

medium Tenable Self-Hosted Container Security Plugin ID 464376

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- A flaw was found in the admin-ui-ext component of Keycloak, which provides extended administrative user
interface capabilities. The issue occurs because certain bulk role-removal endpoints fail to perform
granular permission checks when deleting role mappings. This allows a delegated administrator with limited
permissions to remove highly privileged roles from other users or groups, potentially disrupting
administrative access control. (CVE-2026-11986)

Solution

Update the org.keycloak:keycloak-rest-admin-ui-ext library and its related packages to version 26.7.0 or later.

See Also

https://advisory.echohq.com/cve/CVE-2026-11986

Plugin Details

Severity: Medium

ID: 464376

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/3/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.76

CVSS v2

Risk Factor: Medium

Base Score: 6.1

Temporal Score: 4.5

Vector: CVSS2#AV:N/AC:L/Au:M/C:N/I:C/A:N

CVSS Score Source: CVE-2026-11986

CVSS v3

Risk Factor: Medium

Base Score: 4.9

Temporal Score: 4.3

Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 9/28/2026

Vulnerability Publication Date: 6/11/2026

Reference Information

CVE: CVE-2026-11986