PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-18571 Red Hat CVE debrief

A flaw was found in the user creation component of Keycloak when Fine-Grained Admin Permissions V2 (FGAP V2) is enabled. This issue allows a sub-administrator with permission to create users to add those users to any group, even groups the sub-administrator is not authorized to manage. The vulnerability could lead to unauthorized access to sensitive information or elevated privileges for the newly created users. Defenders should verify affected Keycloak instances, review sub-administrator permissions, and restrict access to sensitive groups. Evidence from Redhat indicates a potential vulnerability in Keycloak's user creation component when Fine-Grained Admin Permissions V2 (FGAP V2) is enabled. The issue allows a sub-administrator with permission to create users to add those users to any group, even groups the sub-administrator is not authorized to manage. This could lead to unauthorized access to sensitive information or elevated privileges for the newly created users. Defenders should verify affected Keycloak instances, review sub-administrator permissions, and restrict access to sensitive groups.

Vendor
Red Hat
Product
Red Hat Build of Keycloak
CVSS
MEDIUM 6.6
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-02
Original CVE updated
2026-08-02
Advisory published
2026-08-02
Advisory updated
2026-08-02

Who should care

Administrators of Keycloak instances with Fine-Grained Admin Permissions V2 (FGAP V2) enabled should review and restrict sub-administrator permissions to prevent unauthorized access. Security teams and vulnerability management teams should also be aware of the potential impact and review affected systems for exposure.

Technical summary

The vulnerability exists in the user creation component of Keycloak when Fine-Grained Admin Permissions V2 (FGAP V2) is enabled. A sub-administrator with permission to create users can add those users to any group, even groups they are not authorized to manage. This could lead to unauthorized access to sensitive information or elevated privileges for the newly created users. The issue requires review of sub-administrator permissions and access controls to prevent exploitation.

Defensive priority

Medium priority due to potential unauthorized access

Recommended defensive actions

  • Review and restrict sub-administrator permissions
  • Monitor user creation and group assignment
  • Implement compensating controls for access management
  • Verify affected Keycloak instances exist in managed environments
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

Evidence from Redhat indicates a potential vulnerability in Keycloak's user creation component when Fine-Grained Admin Permissions V2 (FGAP V2) is enabled. The issue allows a sub-administrator with permission to create users to add those users to any group, even groups the sub-administrator is not authorized to manage. This could lead to unauthorized access to sensitive information or elevated privileges for the newly created users. Defenders should verify affected Keycloak instances, review sub-administrator permissions, and restrict access to sensitive groups.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-02T06:16:42.000Z and has not been modified since then.