Red Hat Keycloak: improper access control
Medium4.3CVE-2026-14613 · Published Jul 3, 2026 · updated Aug 31, 2026
A vulnerability was discovered in Keycloak's administrative interface that allows certain administrators to see information about groups they shouldn't have access to. When the new Fine-Grained Admin Permissions (FGAP v2) are turned on, an administrator who is allowed to see a specific "role" can also see a list of all groups assigned to that role. The system fails to check if the administrator has permission to see those specific groups. This could allow a restricted administrator to discover "hidden" groups and see their details, such as internal names and custom settings, which might contain sensitive deployment information.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Red Hat Build of Keycloak Product | all versions | No fix yet |
| all versions | No fix yet | |
| Red Hat Data Grid 8 Product | all versions | No fix yet |
| Red Hat JBoss Enterprise Application Platform Expansion Pack Product | all versions | No fix yet |
| Red Hat Single Sign-On 7 Product | all versions | No fix yet |
| Red Hat build of Keycloak 26.6.6 Product | all versions | No fix yet |
Details and references
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 3 | Red Hat GIMP: buffer overflow | High7.3 | No fix yet |
| Jul 3 | Red Hat ClientResource: insecure direct object reference | Medium5.4 | No fix yet |
| Jul 3 | A flaw was found in the Fine-Grained Admin Permissions | Medium4.3 | No fix yet |
| Jul 3 | Red Hat Enterprise Linux: denial of service | Medium4.2 | No fix yet |
| Jul 3 | Red Hat HPLIP: privilege escalation | Critical9.8 | No fix yet |
| Jul 2 | Red Hat GIMP: memory corruption | Medium6.1 | No fix yet |