漏洞概述 漏洞名称: CVE-2026-9796 漏洞类型: Time-of-Check to Time-of-Use (TOCTOU) 漏洞 描述: 在 Keycloak 中,一个具有 角色的经过身份验证的管理员可以利用基于名称的管理员角色检查中的 TOCTOU 漏洞。这允许攻击者将其权限提升到 ,从而获得对系统中所有用户的广泛控制。复合角色关系在攻击者自己的权限被撤销和系统重启后仍然存在。 影响范围 产品: Security Response 组件: vulnerability 操作系统: Linux 优先级: medium 严重程度: medium 目标里程碑: --- 分配给: Product Security DevOps Team 修复方案 报告日期: 2026-05-28 03:33 UTC by OSIDB Bzimport 修改日期: 2026-05-28 04:23 UTC CC 列表: 10 users 修复版本: --- 关闭版本: --- 环境: --- 最后关闭: --- Embargoed: --- POC 代码或利用代码 页面中未包含 POC 代码或利用代码。 其他信息 关键词: Security Response 别名: CVE-2026-9796 硬件: All QA 联系人: --- 文档联系人: --- URL: --- 白名单: --- 依赖项: --- 阻塞项: --- 树视图: depends on / blocked 附件 附件名称: (Terms of Use) 描述: A flaw was found in Keycloak. An authenticated administrator with the role can exploit a Time-of-check to time-of-use (TOCTOU) vulnerability in the name-based admin role checks. This allows the attacker to escalate their privileges to for all users within the realm, granting them extensive control over the system. The composite role relationship persists even after the attacker's own permissions are revoked and across system reboots. 备注 需要登录才能在此漏洞上发表评论或进行更改。