Description


A flaw was found in the Fine-Grained Admin Permissions (FGAP) v2 implementation within Keycloak's administrative services. When FGAP v2 is enabled, the system fails to properly filter child groups based on the caller's specific permissions when requested through a parent group. This allows a delegated administrator to view details of child groups they are not authorized to access directly, including group names, paths, and custom attributes.

Related CPE's


a

redhat

build_of_keycloak

2

Weaknesses



CWE-1220

CVSS impact metrics


CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

4.3 · Medium

Information


Source identifier

[email protected]

Vulnerability status

Analyzed

Published

2026-07-03T16:16:55.773Z

3 months ago

Last modified

2026-08-11T14:45:58.313Z

1 month ago