Skip to content
Red HatCVE-2026-15945

Red Hat Data Grid 8: insecure direct object reference

Medium4.3CVE-2026-15945 · Published Jul 16, 2026 · updated Sep 16, 2026

A flaw was found in the group search functionality of the Keycloak server's administrative API. When Fine-Grained Admin Permissions (FGAP) v2 is enabled, a delegated administrator can bypass access restrictions to view parent groups they are not authorized to see. By searching for a child group they have permission to view, the system incorrectly returns the full details of the parent group in the response, leading to the disclosure of sensitive group attributes and configuration.

Red Hat advisory

Affected versions

PackageAffectedFixed in
Red Hat Data Grid 8
Product
all versionsNo fix yet
Red Hat JBoss Enterprise Application Platform Expansion Pack
Product
all versionsNo fix yet
Red Hat Single Sign-On 7
Product
all versionsNo fix yet
Red Hat build of Keycloak 26.6.7
Product
all versionsNo fix yet
all versionsNo fix yet
all versionsNo fix yet
Details and references

More Red Hat advisories

All Red Hat
Advisory
Red Hat PipeWire: code execution
High8.8Jul 16
Red Hat Keycloak.: improper access control
High8.1Jul 16
Red Hat Feast Feature Server: denial of service
High7.5Jul 16
Red Hat libsolv: stack buffer overflow
High7.5Jul 16
Red Hat AAP Gateway Envoy proxy configuration: authentication bypass by spoofing
High8.2Jul 15
Red Hat samba: denial of service
Medium6.1Jul 15

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.