---
id: CVE-2026-11577
title: >-
  Rejected reason: The reported behavior does not constitute a privilege
  escalation
summary: >-
  Rejected reason: The reported behavior does not constitute a privilege
  escalation. Exploitation requires the attacker to already possess the
  manage-realm administrative role within the realm-management client. By
  design, the manage-realm…
severity: none
published: '2026-06-08'
updated: '2026-07-03'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-11577'
tags:
  - nvd
epss: 0.00329
epssPercentile: 0.24811
ingestedAt: '2026-07-03T13:02:27.771Z'
---

## Overview

Rejected reason: The reported behavior does not constitute a privilege escalation. Exploitation requires the attacker to already possess the manage-realm administrative role within the realm-management client. By design, the manage-realm role is intended to be equivalent in administrative authority to realm-admin. A user with manage-realm already has full administrative control over the realm. Therefore, importing users with realm-admin role mappings through POST /admin/realms/{realm}/partialImport does not grant any additional privileges beyond those already held by the administrator and does not represent a security vulnerability.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
