CVE-2026-11577EPSS p24.8%

CVE-2026-11577CVE-2026-11577

Description

Rejected reason: The reported behavior does not constitute a privilege escalation. Exploitation requires the attacker to already possess the manage-realm administrative role within the realm-management client. By design, the manage-realm role is intended to be equivalent in administrative authority to realm-admin. A user with manage-realm already has full administrative control over the realm. Therefore, importing users with realm-admin role mappings through POST /admin/realms/{realm}/partialImport does not grant any additional privileges beyond those already held by the administrator and does not represent a security vulnerability.

Scoring

EPSS0.33% probability of exploitation · percentile 24.8% · 2026-07-03T12:00:25Z
Last modified2026-07-03

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2026-9795
CVE
CVE-2026-37978
CVE
CVE-2026-9088
CVE
CVE-2026-7571
CVE
CVE-2026-8830
CVE
CVE-2026-9796
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.