Insufficient Granularity of Access Control in Red Hat build of Keycloak - CVE-2026-14615
Published: September 11, 2026
Vulnerability details
The vulnerability allows a remote user to disclose restricted group metadata and attributes.
The vulnerability exists due to an improper conditional check in group retrieval logic in Keycloak administrative services when retrieving child groups through a parent group. A remote user can request child groups through a parent group to disclose restricted group metadata and attributes.
Fine-Grained Admin Permissions v2 must be enabled.