Authorization bypass through user-controlled key in Keycloak - CVE-2026-15945
Published: September 10, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive group attributes and configuration.
The vulnerability exists due to authorization bypass through a user-controlled key in the group search functionality of the Keycloak server administrative API when searching for a child group the user is authorized to view. A remote user can search for an authorized child group to view full details of an unauthorized parent group and disclose sensitive group attributes and configuration.
Fine-Grained Admin Permissions v2 must be enabled.