Aller au contenu

Fiche vulnérabilité

CVE-2026-14613 : faille moyenne redhat build of keycloak (CVSS 4.9)

Description

A vulnerability was discovered in Keycloak's administrative interface that allows certain administrators to see information about groups they shouldn't have access to. When the new Fine-Grained Admin Permissions (FGAP v2) are turned on, an administrator who is allowed to see a specific "role" can also see a list of all groups assigned to that role. The system fails to check if the administrator has permission to see those specific groups. This could allow a restricted administrator to discover "hidden" groups and see their details, such as internal names and custom settings, which might contain sensitive deployment information.

En bref

Sévérité
Moyenne (CVSS 4.9)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Exploitation active
Non signalée par la CISA
Publication
3 juil. 2026
Dernière mise à jour
31 août 2026

Produits concernés

  • redhat build of keycloak

Références

Rechercher une autre vulnérabilité dans la base CVE