Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-14613

Опубликовано: 03 июл. 2026
Источник: redhat
CVSS3: 4.3
EPSS Низкий

Описание

A vulnerability was discovered in Keycloak's administrative interface that allows certain administrators to see information about groups they shouldn't have access to. When the new Fine-Grained Admin Permissions (FGAP v2) are turned on, an administrator who is allowed to see a specific "role" can also see a list of all groups assigned to that role. The system fails to check if the administrator has permission to see those specific groups. This could allow a restricted administrator to discover "hidden" groups and see their details, such as internal names and custom settings, which might contain sensitive deployment information.

Отчет

The Red Hat Product Security team has assessed the severity of this vulnerability as Moderate. While it allows for an unauthorized disclosure of group metadata, it requires the attacker to already possess a delegated administrative role with specific view permissions. The vulnerability is a result of a missing authorization check in the RoleContainerResource component when FGAP v2 is active. Direct access to the hidden groups remains protected; the leak occurs only through the role-to-group mapping enumeration endpoint.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Build of Keycloakkeycloak-servicesNot affected
Red Hat Build of Keycloakrhbk/keycloak-rhel9Affected
Red Hat Build of Keycloakrhbk-openshift-rhel9/rhbk-openshift-rhel9Not affected
Red Hat Data Grid 8keycloak-servicesNot affected
Red Hat JBoss Enterprise Application Platform Expansion Packkeycloak-servicesNot affected
Red Hat Single Sign-On 7keycloak-servicesNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=2496878keycloak-services: keycloak-services: Keycloak: FGAP v2 role groups endpoint discloses hidden group metadata without group view permission

EPSS

Процентиль: 8%
0.0018
Низкий

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
ubuntu
около 2 месяцев назад

A vulnerability was discovered in Keycloak's administrative interface that allows certain administrators to see information about groups they shouldn't have access to. When the new Fine-Grained Admin Permissions (FGAP v2) are turned on, an administrator who is allowed to see a specific "role" can also see a list of all groups assigned to that role. The system fails to check if the administrator has permission to see those specific groups. This could allow a restricted administrator to discover "hidden" groups and see their details, such as internal names and custom settings, which might contain sensitive deployment information.

CVSS3: 4.3
nvd
около 2 месяцев назад

A vulnerability was discovered in Keycloak's administrative interface that allows certain administrators to see information about groups they shouldn't have access to. When the new Fine-Grained Admin Permissions (FGAP v2) are turned on, an administrator who is allowed to see a specific "role" can also see a list of all groups assigned to that role. The system fails to check if the administrator has permission to see those specific groups. This could allow a restricted administrator to discover "hidden" groups and see their details, such as internal names and custom settings, which might contain sensitive deployment information.

CVSS3: 4.3
debian
около 2 месяцев назад

A vulnerability was discovered in Keycloak's administrative interface ...

CVSS3: 4.3
github
около 2 месяцев назад

A vulnerability was discovered in Keycloak's administrative interface that allows certain administrators to see information about groups they shouldn't have access to. When the new Fine-Grained Admin Permissions (FGAP v2) are turned on, an administrator who is allowed to see a specific "role" can also see a list of all groups assigned to that role. The system fails to check if the administrator has permission to see those specific groups. This could allow a restricted administrator to discover "hidden" groups and see their details, such as internal names and custom settings, which might contain sensitive deployment information.

EPSS

Процентиль: 8%
0.0018
Низкий

4.3 Medium

CVSS3