Junglewise Threat Intelligence

CVE-2026-18571: Keycloak privilege escalation in user creation with FGAP V2

CVE-2026-18571 · Severity: medium · CVSS 6.6 · Published 2026-08-02

Technologies: Red Hat Keycloak. Vendors: Red Hat.

Executive brief

Keycloak is an open-source identity and access management system used to secure applications and APIs. When Fine-Grained Admin Permissions V2 is enabled, a sub-administrator with permission to create users can assign those users to any group—including groups they are not authorized to access—potentially granting them unauthorized privileges or access to sensitive information.

Technical details

The vulnerability is a privilege escalation flaw in Keycloak's user creation component when Fine-Grained Admin Permissions V2 (FGAP V2) is enabled. A sub-administrator with user creation permissions can exploit improper authorization checks to add newly created users to any group, regardless of whether the sub-administrator is authorized to manage that group. This allows an attacker to bypass group access controls and grant elevated privileges to accounts they control. The issue requires the attacker to have existing sub-administrator credentials with user creation rights. A patch or mitigation is likely available from Red Hat/Keycloak maintainers.

Affected products

  • Red Hat Keycloak

Timeline

  • 2026-08-02: disclosed

References