Insufficient Granularity of Access Control in Keycloak - CVE-2026-14613
Published: September 10, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive group information.
The vulnerability exists due to insufficient granularity of access control in Keycloak\'s administrative interface when viewing groups assigned to a role. A remote user can view groups assigned to a role they are permitted to view to disclose sensitive group information.
Only instances with Fine-Grained Admin Permissions version 2 enabled are affected.