Skip to content
Red HatCVE-2026-14615

A flaw was found in the Fine-Grained Admin Permissions

Medium4.3CVE-2026-14615 · Published Jul 3, 2026 · updated Aug 11, 2026

A flaw was found in the Fine-Grained Admin Permissions (FGAP) v2 implementation within Keycloak's administrative services. When FGAP v2 is enabled, the system fails to properly filter child groups based on the caller's specific permissions when requested through a parent group. This allows a delegated administrator to view details of child groups they are not authorized to access directly, including group names, paths, and custom attributes.

Red Hat advisory

Affected versions

PackageAffectedFixed in
Red Hat build of Keycloak 26.4.14
Product
all versionsNo fix yet
Red Hat build of Keycloak 26.6.5
Product
all versionsNo fix yet
Details and references

More Red Hat advisories

All Red Hat
Advisory
Red Hat GIMP: buffer overflow
High7.3Jul 3
Red Hat Keycloak: improper access control
Medium4.3Jul 3
Red Hat ClientResource: insecure direct object reference
Medium5.4Jul 3
Red Hat Enterprise Linux: denial of service
Medium4.2Jul 3
Red Hat HPLIP: privilege escalation
Critical9.8Jul 3
Red Hat GIMP: memory corruption
Medium6.1Jul 2

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.