Description
A flaw was found in the Fine-Grained Admin Permissions (FGAP) v2 implementation within Keycloak's administrative services. When FGAP v2 is enabled, the system fails to properly filter child groups based on the caller's specific permissions when requested through a parent group. This allows a delegated administrator to view details of child groups they are not authorized to access directly, including group names, paths, and custom attributes.
Related CPE's
a
redhat
build_of_keycloak
References
https://access.redhat.com/errata/RHSA-2026:50846
https://access.redhat.com/errata/RHSA-2026:50847
https://access.redhat.com/errata/RHSA-2026:50848
https://access.redhat.com/errata/RHSA-2026:50849
https://access.redhat.com/security/cve/CVE-2026-14615
https://bugzilla.redhat.com/show_bug.cgi?id=2496891
CVSS impact metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
4.3 · Medium
Information
Source identifier
Vulnerability status
Analyzed
Published
2026-07-03T16:16:55.773Z
3 months agoLast modified
2026-08-11T14:45:58.313Z
1 month ago