Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-18571

Опубликовано: 02 авг. 2026
Источник: nvd
CVSS3: 6.6
CVSS3: 7.2
EPSS Низкий

Описание

A flaw was found in the user creation component of Keycloak when Fine-Grained Admin Permissions V2 (FGAP V2) is enabled. This issue allows a sub-administrator with permission to create users to add those users to any group, even groups the sub-administrator is not authorized to manage. This could lead to unauthorized access to sensitive information or elevated privileges for the newly created users.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:redhat:build_of_keycloak:-:*:*:*:-:*:*:*

EPSS

Процентиль: 16%
0.00245
Низкий

6.6 Medium

CVSS3

7.2 High

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 6.6
redhat
18 дней назад

A flaw was found in the user creation component of Keycloak when Fine-Grained Admin Permissions V2 (FGAP V2) is enabled. This issue allows a sub-administrator with permission to create users to add those users to any group, even groups the sub-administrator is not authorized to manage. This could lead to unauthorized access to sensitive information or elevated privileges for the newly created users.

CVSS3: 6.6
debian
15 дней назад

A flaw was found in the user creation component of Keycloak when Fine- ...

CVSS3: 6.6
github
15 дней назад

A flaw was found in the user creation component of Keycloak when Fine-Grained Admin Permissions V2 (FGAP V2) is enabled. This issue allows a sub-administrator with permission to create users to add those users to any group, even groups the sub-administrator is not authorized to manage. This could lead to unauthorized access to sensitive information or elevated privileges for the newly created users.

EPSS

Процентиль: 16%
0.00245
Низкий

6.6 Medium

CVSS3

7.2 High

CVSS3

Дефекты

CWE-862