CVE-2026-18571

A flaw was found in the user creation component of Keycloak when Fine-Grained Admin Permissions V2 (FGAP V2) is enabled. This issue allows a sub-administrator with permission to create users to add those users to any group, even groups the sub-administrator is not authorized to manage. This could lead to unauthorized access to sensitive information or elevated privileges for the newly created users.
Configurations

Configuration 1 (hide)

cpe:2.3:a:redhat:build_of_keycloak:-:*:*:*:-:*:*:*

History

16 Sep 2026, 16:17

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:68277 -
  • () https://access.redhat.com/errata/RHSA-2026:68278 -

Information

Published : 2026-08-02 06:16

Updated : 2026-09-16 16:17


NVD link : CVE-2026-18571

Mitre link : CVE-2026-18571

CVE.ORG link : CVE-2026-18571


JSON object : View

Products Affected

redhat

  • build_of_keycloak
CWE
CWE-862

Missing Authorization