Junglewise Threat Intelligence

CVE-2026-16108: Red Hat Keycloak information disclosure in default-groups REST endpoint

CVE-2026-16108 · Severity: medium · CVSS 4.3 · Published 2026-07-17

Technologies: Red Hat build of Keycloak. Vendors: Red Hat.

Executive brief

Keycloak is an open-source identity and access management solution used to manage user authentication and authorization. A security flaw allows certain administrative users to see the names and identifiers of internal groups they are not supposed to access. This could lead to the exposure of sensitive organizational structures or internal group hierarchies to unauthorized staff.

Technical details

An information disclosure vulnerability exists in the Keycloak Admin REST API when Fine-Grained Admin Permissions (FGAP) v2 is enabled. The 'default-groups' endpoint and general realm representation fail to correctly enforce per-group view permission checks for groups designated as 'default'. An authenticated attacker with realm-level view permissions can bypass specific group-level restrictions to enumerate group names, UUIDs, and paths. This allows for the mapping of the authorization topology and internal organizational structures. The issue is tracked as CVE-2026-16108 and primarily affects the 'keycloak-services' component.

Affected products

  • Red Hat Build of Keycloak unspecified

Timeline

  • 2026-07-17: disclosed: CVE published and reported to Red Hat Bugzilla

References

Related threats