Junglewise Threat Intelligence

CVE-2026-15945: Red Hat Keycloak authorization bypass in group search API

CVE-2026-15945 · Severity: medium · CVSS 4.3 · Published 2026-07-16

Technologies: Red Hat build of Keycloak, Red Hat Single Sign-On 7, Red Hat Data Grid 8, Red Hat build of Keycloak. Vendors: Red Hat.

Executive brief

A security flaw in Keycloak's administrative interface allows certain low-privileged administrators to view information they should not have access to. Specifically, an administrator with permission to see a sub-group can bypass restrictions to view the full details, configuration, and sensitive attributes of the parent group. This could lead to the exposure of internal organizational structures and sensitive metadata.

Technical details

An information disclosure vulnerability exists in the Keycloak administrative API's group search functionality (GET /admin/realms/{realm}/groups). When Fine-Grained Admin Permissions (FGAP) v2 is enabled, the system fails to properly filter parent group details in the search response hierarchy. An attacker with 'query-groups' permissions and 'view' permissions on a child group can use the search parameter with 'briefRepresentation=false' to retrieve the full details of unauthorized parent groups. This includes internal UUIDs, custom group attributes, and role mappings that should otherwise be restricted.

Affected products

  • Red Hat Red Hat Build of Keycloak
  • Red Hat Red Hat Single Sign-On 7
  • Red Hat Red Hat Data Grid 8
  • Red Hat Red Hat JBoss Enterprise Application Platform Expansion Pack

Timeline

  • 2026-07-16: disclosed
  • 2026-07-16: advisory

References

Related threats