Skip to content
Red HatCVE-2026-14614

Red Hat ClientResource: insecure direct object reference

Medium5.4CVE-2026-14614 · Published Jul 3, 2026 · updated Aug 11, 2026

A flaw was found in the ClientResource component of Keycloak's admin services when Fine-Grained Admin Permissions (FGAP) v2 is enabled. This issue allows a delegated administrator, who should only have limited control over specific clients, to attach or remove hidden client scopes that they are not authorized to see or manage. As a result, an attacker could inject unauthorized data or permissions into the security tokens issued to end-users, potentially tricking other applications into granting higher levels of access than intended.

Red Hat advisory

Affected versions

PackageAffectedFixed in
Red Hat Build of Keycloak
Product
all versionsNo fix yet
all versionsNo fix yet
Red Hat Data Grid 8
Product
all versionsNo fix yet
Red Hat JBoss Enterprise Application Platform Expansion Pack
Product
all versionsNo fix yet
Red Hat build of Keycloak 26.4.14
Product
all versionsNo fix yet
Red Hat build of Keycloak 26.6.5
Product
all versionsNo fix yet
Details and references

More Red Hat advisories

All Red Hat
Advisory
Red Hat GIMP: buffer overflow
High7.3Jul 3
Red Hat Keycloak: improper access control
Medium4.3Jul 3
A flaw was found in the Fine-Grained Admin Permissions
Medium4.3Jul 3
Red Hat Enterprise Linux: denial of service
Medium4.2Jul 3
Red Hat HPLIP: privilege escalation
Critical9.8Jul 3
Red Hat GIMP: memory corruption
Medium6.1Jul 2

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.