A flaw was found in the Fine-Grained Admin Permissions (FGAP) v2 implementation within Keycloak's administrative services. When FGAP v2 is enabled, the system fails to properly filter child groups based on the caller's specific permissions when requested through a parent group. This allows a delegated administrator to view details of child groups they are not authorized to access directly, including group names, paths, and custom attributes.
References
| Link | Resource |
|---|---|
| https://access.redhat.com/errata/RHSA-2026:50846 | Vendor Advisory |
| https://access.redhat.com/errata/RHSA-2026:50847 | Vendor Advisory |
| https://access.redhat.com/errata/RHSA-2026:50848 | Vendor Advisory |
| https://access.redhat.com/errata/RHSA-2026:50849 | Vendor Advisory |
| https://access.redhat.com/security/cve/CVE-2026-14615 | Vendor Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2496891 | Issue Tracking Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2026-07-03 16:16
Updated : 2026-08-11 14:45
NVD link : CVE-2026-14615
Mitre link : CVE-2026-14615
CVE.ORG link : CVE-2026-14615
JSON object : View
Products Affected
redhat
- build_of_keycloak
CWE
CWE-1220
Insufficient Granularity of Access Control
