PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-14615 Red Hat CVE debrief

A flaw was found in the Fine-Grained Admin Permissions (FGAP) v2 implementation within Keycloak's administrative services. When FGAP v2 is enabled, the system fails to properly filter child groups based on the caller's specific permissions when requested through a parent group. This allows a delegated administrator to view details of child groups they are not authorized to access directly, including group names, paths, and custom attributes.

Vendor
Red Hat
Product
Red Hat build of Keycloak 26.4
CVSS
MEDIUM 4.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-03
Original CVE updated
2026-08-05
Advisory published
2026-07-03
Advisory updated
2026-08-05

Who should care

Administrators and security teams responsible for Keycloak deployments, especially those using Fine-Grained Admin Permissions (FGAP) v2, should be aware of this vulnerability and take steps to mitigate potential risks. They should review and update Keycloak administrative service configurations to ensure proper filtering of child groups based on caller permissions. Additional monitoring should be implemented to detect and respond to potential unauthorized access attempts. Available patches or updates from the vendor should be verified and applied. Keycloak deployments should verify their configurations and ensure proper filtering of child groups based on caller permissions to prevent unauthorized access to sensitive group information. Security teams should also review compensating controls for exposed systems while remediation is scheduled and verified. Monitoring, detection, and logs for exposed assets should be checked for extra review. Exceptions, retest remediated assets, and close the item only after evidence is documented. This vulnerability has a CVSS score of 4.3 and is classified as MEDIUM severity, indicating a medium priority for remediation efforts. However, given the potential for unauthorized access to sensitive group information, it is essential to address this vulnerability promptly and thoroughly. Affected operator, platform, vulnerability-management, and security-team impact should be carefully evaluated to ensure effective mitigation and remediation of this vulnerability. The Fine-Grained Admin Permissions (FGAP) v2 implementation in Keycloak's administrative services has a flaw that allows delegated administrators to view details of child groups they are not authorized to access directly. This occurs when FGAP v2 is enabled and the system fails to properly filter child groups based on the caller's specific permissions when requested through a parent group. The vulnerability has a CVSS score of 4.3 and is classified as MEDIUM severity. Administrators and security teams responsible for Keycloak deployments should review and update their configurations to ensure proper filtering of child groups based on caller permissions. Additional monitoring,

Technical summary

The Fine-Grained Admin Permissions (FGAP) v2 implementation in Keycloak's administrative services has a flaw that allows delegated administrators to view details of child groups they are not authorized to access directly. This occurs when FGAP v2 is enabled and the system fails to properly filter child groups based on the caller's specific permissions when requested through a parent group. The vulnerability has a CVSS score of 4.3 and is classified as MEDIUM severity. Administrators and security teams responsible for Keycloak deployments should review and update their configurations to ensure proper filtering of child groups based on caller permissions.

Defensive priority

Medium priority given the CVSS score of 4.3 and the potential for unauthorized access to sensitive group information.

Recommended defensive actions

  • Review and update Keycloak administrative service configurations to ensure proper filtering of child groups based on caller permissions.
  • Implement additional monitoring to detect and respond to potential unauthorized access attempts.
  • Verify and apply any available patches or updates from the vendor.
  • Confirm whether affected Keycloak deployments exist in managed environments and assign an owner for follow-up.
  • Review compensating controls for exposed Keycloak systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed Keycloak assets that need extra review.
  • Track exceptions, retest remediated Keycloak assets, and close the item only after evidence is documented.

Evidence notes

Evidence is based on limited information from the NVD and a few Red Hat references. Further investigation is needed to fully understand the vulnerability's impact and affected systems. The vulnerability allows delegated administrators to view details of child groups they are not authorized to access directly, including group names, paths, and custom attributes. This occurs when FGAP v2 is enabled and the system fails to properly filter child groups based on the caller's specific permissions when requested through a parent group. Keycloak deployments, especially those using Fine-Grained Admin Permissions (FGAP) v2, should verify their configurations and ensure proper filtering of child groups based on caller permissions.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-03T16:16:55.773Z and has not been modified since then. The NVD entry is currently Awaiting Analysis.