Executive brief
Keycloak is an open-source identity and access management solution used to manage user authentication and authorization. A security flaw allows certain administrative users to see the names and identifiers of internal groups they are not supposed to access. This could lead to the exposure of sensitive organizational structures or internal group hierarchies to unauthorized staff.
Technical details
An information disclosure vulnerability exists in the Keycloak Admin REST API when Fine-Grained Admin Permissions (FGAP) v2 is enabled. The 'default-groups' endpoint and general realm representation fail to correctly enforce per-group view permission checks for groups designated as 'default'. An authenticated attacker with realm-level view permissions can bypass specific group-level restrictions to enumerate group names, UUIDs, and paths. This allows for the mapping of the authorization topology and internal organizational structures. The issue is tracked as CVE-2026-16108 and primarily affects the 'keycloak-services' component.
Affected products
- Red Hat Build of Keycloak unspecified
Timeline
- 2026-07-17: disclosed: CVE published and reported to Red Hat Bugzilla