Insufficient Granularity of Access Control in Keycloak - CVE-2026-16108
Published: July 17, 2026 / Updated: September 5, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to insufficient granularity of access control in the default-groups REST endpoint and realm representation when handling requests from delegated administrators with realm-viewing permissions. A remote user can access the names and identifiers of hidden default groups to disclose sensitive information.