Red HatCVE-2026-14615
A flaw was found in the Fine-Grained Admin Permissions
Medium4.3CVE-2026-14615 · Published Jul 3, 2026 · updated Aug 11, 2026
A flaw was found in the Fine-Grained Admin Permissions (FGAP) v2 implementation within Keycloak's administrative services. When FGAP v2 is enabled, the system fails to properly filter child groups based on the caller's specific permissions when requested through a parent group. This allows a delegated administrator to view details of child groups they are not authorized to access directly, including group names, paths, and custom attributes.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Red Hat build of Keycloak 26.4.14 Product | all versions | No fix yet |
| Red Hat build of Keycloak 26.6.5 Product | all versions | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-1220
- www.cve.org/CVERecord?id=CVE-2026-14615
- nvd.nist.gov/vuln/detail/CVE-2026-14615
- access.redhat.com/errata/RHSA-2026:50846
- access.redhat.com/errata/RHSA-2026:50847
- access.redhat.com/errata/RHSA-2026:50848
- access.redhat.com/errata/RHSA-2026:50849
- access.redhat.com/security/cve/CVE-2026-14615
- bugzilla.redhat.com/show_bug.cgi?id=2496891
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 3 | Red Hat GIMP: buffer overflow | High7.3 | No fix yet |
| Jul 3 | Red Hat Keycloak: improper access control | Medium4.3 | No fix yet |
| Jul 3 | Red Hat ClientResource: insecure direct object reference | Medium5.4 | No fix yet |
| Jul 3 | Red Hat Enterprise Linux: denial of service | Medium4.2 | No fix yet |
| Jul 3 | Red Hat HPLIP: privilege escalation | Critical9.8 | No fix yet |
| Jul 2 | Red Hat GIMP: memory corruption | Medium6.1 | No fix yet |