PatchSiren cyber security CVE debrief
CVE-2026-14209 Red Hat CVE debrief
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-06-30T13:17:10.317Z and has not been modified since then. The vulnerability in Keycloak's Admin UI extension allows certain administrative users with search permissions but not view permissions to access a user's full profile, including sensitive information and security metadata, via a specific 'brute-force-user' endpoint when Fine-Grained Admin Permissions (FGAPv2) are enabled. This issue arises from the system failing to check for the required 'view' permission for that specific user when using this search path. Administrators of Keycloak instances with Fine-Grained Admin Permissions (FGAPv2) enabled should be aware of this vulnerability, especially those with users who have search but not view permissions. Red Hat users should check for applicable errata. Evidence from the NVD and Red Hat sources indicates a vulnerability in Keycloak's Admin UI extension allowing certain administrative users to bypass security restrictions when Fine-Grained Admin Permissions (FGAPv2) are enabled. The issue permits access to a user's full profile, including sensitive information and security metadata, via a specific 'brute-force-user' endpoint. However, detailed information about affected versions and patches is limited in the provided corpus. To address this, administrators should prioritize patching Keycloak instances with Fine-Grained Admin Permissions (FGAPv2) enabled, focusing on those with administrative users who have search permissions but not view permissions.
- Vendor
- Red Hat
- Product
- Red Hat build of Keycloak 26.4
- CVSS
- MEDIUM 4.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-30
- Original CVE updated
- 2026-08-05
- Advisory published
- 2026-06-30
- Advisory updated
- 2026-08-05
Who should care
Administrators of Keycloak instances with Fine-Grained Admin Permissions (FGAPv2) enabled should be aware of this vulnerability, especially those with users who have search but not view permissions. Red Hat users should check for applicable errata.
Technical summary
A vulnerability in Keycloak's Admin UI extension allows certain administrative users with search permissions but not view permissions to access a user's full profile, including sensitive information and security metadata, via a specific 'brute-force-user' endpoint when Fine-Grained Admin Permissions (FGAPv2) are enabled. The issue arises from the system failing to check for the required 'view' permission for that specific user when using this search path.
Defensive priority
Administrators should prioritize patching Keycloak instances with Fine-Grained Admin Permissions (FGAPv2) enabled, focusing on those with administrative users who have search permissions but not view permissions.
Recommended defensive actions
- Patch Keycloak instances with Fine-Grained Admin Permissions (FGAPv2) enabled
- Restrict access to the 'brute-force-user' endpoint for users without view permissions
- Monitor for unusual activity on Keycloak administrative interfaces
- Inventory Keycloak instances and verify FGAPv2 settings
- Apply compensating controls to limit exposure of sensitive user data
Evidence notes
Evidence from the NVD and Red Hat sources indicates a vulnerability in Keycloak's Admin UI extension allowing certain administrative users to bypass security restrictions when Fine-Grained Admin Permissions (FGAPv2) are enabled. The issue permits access to a user's full profile, including sensitive information and security metadata, via a specific 'brute-force-user' endpoint. However, detailed information about affected versions and patches is limited in the provided corpus.
Official resources
-
CVE-2026-14209 CVE record
CVE.org
-
CVE-2026-14209 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
- Source reference
- Source reference
- Source reference
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-06-30T13:17:10.317Z and has not been modified since then.