PatchSiren cyber security CVE debrief
CVE-2026-18571 Red Hat CVE debrief
A flaw was found in the user creation component of Keycloak when Fine-Grained Admin Permissions V2 (FGAP V2) is enabled. This issue allows a sub-administrator with permission to create users to add those users to any group, even groups the sub-administrator is not authorized to manage. The vulnerability could lead to unauthorized access to sensitive information or elevated privileges for the newly created users. Defenders should verify affected Keycloak instances, review sub-administrator permissions, and restrict access to sensitive groups. Evidence from Redhat indicates a potential vulnerability in Keycloak's user creation component when Fine-Grained Admin Permissions V2 (FGAP V2) is enabled. The issue allows a sub-administrator with permission to create users to add those users to any group, even groups the sub-administrator is not authorized to manage. This could lead to unauthorized access to sensitive information or elevated privileges for the newly created users. Defenders should verify affected Keycloak instances, review sub-administrator permissions, and restrict access to sensitive groups.
- Vendor
- Red Hat
- Product
- Red Hat Build of Keycloak
- CVSS
- MEDIUM 6.6
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-02
- Original CVE updated
- 2026-08-02
- Advisory published
- 2026-08-02
- Advisory updated
- 2026-08-02
Who should care
Administrators of Keycloak instances with Fine-Grained Admin Permissions V2 (FGAP V2) enabled should review and restrict sub-administrator permissions to prevent unauthorized access. Security teams and vulnerability management teams should also be aware of the potential impact and review affected systems for exposure.
Technical summary
The vulnerability exists in the user creation component of Keycloak when Fine-Grained Admin Permissions V2 (FGAP V2) is enabled. A sub-administrator with permission to create users can add those users to any group, even groups they are not authorized to manage. This could lead to unauthorized access to sensitive information or elevated privileges for the newly created users. The issue requires review of sub-administrator permissions and access controls to prevent exploitation.
Defensive priority
Medium priority due to potential unauthorized access
Recommended defensive actions
- Review and restrict sub-administrator permissions
- Monitor user creation and group assignment
- Implement compensating controls for access management
- Verify affected Keycloak instances exist in managed environments
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
Evidence from Redhat indicates a potential vulnerability in Keycloak's user creation component when Fine-Grained Admin Permissions V2 (FGAP V2) is enabled. The issue allows a sub-administrator with permission to create users to add those users to any group, even groups the sub-administrator is not authorized to manage. This could lead to unauthorized access to sensitive information or elevated privileges for the newly created users. Defenders should verify affected Keycloak instances, review sub-administrator permissions, and restrict access to sensitive groups.
Official resources
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-02T06:16:42.000Z and has not been modified since then.