PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-14209 Red Hat CVE debrief

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-06-30T13:17:10.317Z and has not been modified since then. The vulnerability in Keycloak's Admin UI extension allows certain administrative users with search permissions but not view permissions to access a user's full profile, including sensitive information and security metadata, via a specific 'brute-force-user' endpoint when Fine-Grained Admin Permissions (FGAPv2) are enabled. This issue arises from the system failing to check for the required 'view' permission for that specific user when using this search path. Administrators of Keycloak instances with Fine-Grained Admin Permissions (FGAPv2) enabled should be aware of this vulnerability, especially those with users who have search but not view permissions. Red Hat users should check for applicable errata. Evidence from the NVD and Red Hat sources indicates a vulnerability in Keycloak's Admin UI extension allowing certain administrative users to bypass security restrictions when Fine-Grained Admin Permissions (FGAPv2) are enabled. The issue permits access to a user's full profile, including sensitive information and security metadata, via a specific 'brute-force-user' endpoint. However, detailed information about affected versions and patches is limited in the provided corpus. To address this, administrators should prioritize patching Keycloak instances with Fine-Grained Admin Permissions (FGAPv2) enabled, focusing on those with administrative users who have search permissions but not view permissions.

Vendor
Red Hat
Product
Red Hat build of Keycloak 26.4
CVSS
MEDIUM 4.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-30
Original CVE updated
2026-08-05
Advisory published
2026-06-30
Advisory updated
2026-08-05

Who should care

Administrators of Keycloak instances with Fine-Grained Admin Permissions (FGAPv2) enabled should be aware of this vulnerability, especially those with users who have search but not view permissions. Red Hat users should check for applicable errata.

Technical summary

A vulnerability in Keycloak's Admin UI extension allows certain administrative users with search permissions but not view permissions to access a user's full profile, including sensitive information and security metadata, via a specific 'brute-force-user' endpoint when Fine-Grained Admin Permissions (FGAPv2) are enabled. The issue arises from the system failing to check for the required 'view' permission for that specific user when using this search path.

Defensive priority

Administrators should prioritize patching Keycloak instances with Fine-Grained Admin Permissions (FGAPv2) enabled, focusing on those with administrative users who have search permissions but not view permissions.

Recommended defensive actions

  • Patch Keycloak instances with Fine-Grained Admin Permissions (FGAPv2) enabled
  • Restrict access to the 'brute-force-user' endpoint for users without view permissions
  • Monitor for unusual activity on Keycloak administrative interfaces
  • Inventory Keycloak instances and verify FGAPv2 settings
  • Apply compensating controls to limit exposure of sensitive user data

Evidence notes

Evidence from the NVD and Red Hat sources indicates a vulnerability in Keycloak's Admin UI extension allowing certain administrative users to bypass security restrictions when Fine-Grained Admin Permissions (FGAPv2) are enabled. The issue permits access to a user's full profile, including sensitive information and security metadata, via a specific 'brute-force-user' endpoint. However, detailed information about affected versions and patches is limited in the provided corpus.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-14209 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-14209

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-14209 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-14209

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.