Improper access control in Keycloak - CVE-2025-14082
Published: September 10, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive role metadata.
The vulnerability exists due to improper access control in the Keycloak Admin REST API /admin/realms/{realm}/roles endpoint when handling requests to retrieve role metadata. A remote privileged user can send a request to the endpoint to disclose sensitive role metadata.
Affected software
Red Hat build of Keycloak
How to mitigate CVE-2025-14082
Red Hat build of Keycloak - update to 26.4.11