CVE-2026-14614

A flaw was found in the ClientResource component of Keycloak's admin services when Fine-Grained Admin Permissions (FGAP) v2 is enabled. This issue allows a delegated administrator, who should only have limited control over specific clients, to attach or remove hidden client scopes that they are not authorized to see or manage. As a result, an attacker could inject unauthorized data or permissions into the security tokens issued to end-users, potentially tricking other applications into granting higher levels of access than intended.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:redhat:build_of_keycloak:*:*:*:*:*:*:*:*
cpe:2.3:a:redhat:build_of_keycloak:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-07-03 16:16

Updated : 2026-08-11 15:06


NVD link : CVE-2026-14614

Mitre link : CVE-2026-14614

CVE.ORG link : CVE-2026-14614


JSON object : View

Products Affected

redhat

  • build_of_keycloak
CWE
CWE-639

Authorization Bypass Through User-Controlled Key

CWE-284

Improper Access Control