Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-15945

Опубликовано: 14 июл. 2026
Источник: redhat
CVSS3: 4.3
EPSS Низкий

Описание

A flaw was found in the group search functionality of the Keycloak server's administrative API. When Fine-Grained Admin Permissions (FGAP) v2 is enabled, a delegated administrator can bypass access restrictions to view parent groups they are not authorized to see. By searching for a child group they have permission to view, the system incorrectly returns the full details of the parent group in the response, leading to the disclosure of sensitive group attributes and configuration.

Отчет

The Red Hat Product Security team has assessed the severity of this vulnerability as Moderate, given that it requires an authenticated attacker with specific delegated administrative permissions and the non-default FGAP v2 feature to be enabled. Successful exploitation allows an attacker to disclose sensitive metadata and configuration details of parent groups they are otherwise restricted from viewing. The vulnerability's root cause is a failure to apply fine-grained access control filters to parent groups during hierarchical search result construction.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Build of Keycloakkeycloak-servicesAffected
Red Hat Build of Keycloakrhbk-keycloak-rhel9/rhbk-keycloak-rhel9Affected
Red Hat Build of Keycloakrhbk-openshift-rhel9/rhbk-openshift-rhel9Affected
Red Hat Data Grid 8keycloak-servicesFix deferred
Red Hat JBoss Enterprise Application Platform Expansion Packkeycloak-servicesFix deferred
Red Hat Single Sign-On 7keycloak-servicesFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-639
https://bugzilla.redhat.com/show_bug.cgi?id=2501302keycloak-services: keycloak-services: Group hierarchy search discloses hidden parent groups under FGAP v2

EPSS

Процентиль: 8%
0.00178
Низкий

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
nvd
около 1 месяца назад

A flaw was found in the group search functionality of the Keycloak server's administrative API. When Fine-Grained Admin Permissions (FGAP) v2 is enabled, a delegated administrator can bypass access restrictions to view parent groups they are not authorized to see. By searching for a child group they have permission to view, the system incorrectly returns the full details of the parent group in the response, leading to the disclosure of sensitive group attributes and configuration.

CVSS3: 4.3
debian
около 1 месяца назад

A flaw was found in the group search functionality of the Keycloak ser ...

CVSS3: 4.3
github
около 1 месяца назад

A flaw was found in the group search functionality of the Keycloak server's administrative API. When Fine-Grained Admin Permissions (FGAP) v2 is enabled, a delegated administrator can bypass access restrictions to view parent groups they are not authorized to see. By searching for a child group they have permission to view, the system incorrectly returns the full details of the parent group in the response, leading to the disclosure of sensitive group attributes and configuration.

EPSS

Процентиль: 8%
0.00178
Низкий

4.3 Medium

CVSS3