PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-14209 Red Hat CVE debrief

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-06-30T13:17:10.317Z and has not been modified since then. The vulnerability in Keycloak's Admin UI extension allows certain administrative users with search permissions but not view permissions to access a user's full profile, including sensitive information and security metadata, via a specific 'brute-force-user' endpoint when Fine-Grained Admin Permissions (FGAPv2) are enabled. This issue arises from the system failing to check for the required 'view' permission for that specific user when using this search path. Administrators of Keycloak instances with Fine-Grained Admin Permissions (FGAPv2) enabled should be aware of this vulnerability, especially those with users who have search but not view permissions. Red Hat users should check for applicable errata. Evidence from the NVD and Red Hat sources indicates a vulnerability in Keycloak's Admin UI extension allowing certain administrative users to bypass security restrictions when Fine-Grained Admin Permissions (FGAPv2) are enabled. The issue permits access to a user's full profile, including sensitive information and security metadata, via a specific 'brute-force-user' endpoint. However, detailed information about affected versions and patches is limited in the provided corpus. To address this, administrators should prioritize patching Keycloak instances with Fine-Grained Admin Permissions (FGAPv2) enabled, focusing on those with administrative users who have search permissions but not view permissions.

Vendor
Red Hat
Product
Red Hat build of Keycloak 26.4
CVSS
MEDIUM 4.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-30
Original CVE updated
2026-08-05
Advisory published
2026-06-30
Advisory updated
2026-08-05

Who should care

Administrators of Keycloak instances with Fine-Grained Admin Permissions (FGAPv2) enabled should be aware of this vulnerability, especially those with users who have search but not view permissions. Red Hat users should check for applicable errata.

Technical summary

A vulnerability in Keycloak's Admin UI extension allows certain administrative users with search permissions but not view permissions to access a user's full profile, including sensitive information and security metadata, via a specific 'brute-force-user' endpoint when Fine-Grained Admin Permissions (FGAPv2) are enabled. The issue arises from the system failing to check for the required 'view' permission for that specific user when using this search path.

Defensive priority

Administrators should prioritize patching Keycloak instances with Fine-Grained Admin Permissions (FGAPv2) enabled, focusing on those with administrative users who have search permissions but not view permissions.

Recommended defensive actions

  • Patch Keycloak instances with Fine-Grained Admin Permissions (FGAPv2) enabled
  • Restrict access to the 'brute-force-user' endpoint for users without view permissions
  • Monitor for unusual activity on Keycloak administrative interfaces
  • Inventory Keycloak instances and verify FGAPv2 settings
  • Apply compensating controls to limit exposure of sensitive user data

Evidence notes

Evidence from the NVD and Red Hat sources indicates a vulnerability in Keycloak's Admin UI extension allowing certain administrative users to bypass security restrictions when Fine-Grained Admin Permissions (FGAPv2) are enabled. The issue permits access to a user's full profile, including sensitive information and security metadata, via a specific 'brute-force-user' endpoint. However, detailed information about affected versions and patches is limited in the provided corpus.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-06-30T13:17:10.317Z and has not been modified since then.