Red HatCVE-2026-15945
Red Hat Data Grid 8: insecure direct object reference
Medium4.3CVE-2026-15945 · Published Jul 16, 2026 · updated Sep 16, 2026
A flaw was found in the group search functionality of the Keycloak server's administrative API. When Fine-Grained Admin Permissions (FGAP) v2 is enabled, a delegated administrator can bypass access restrictions to view parent groups they are not authorized to see. By searching for a child group they have permission to view, the system incorrectly returns the full details of the parent group in the response, leading to the disclosure of sensitive group attributes and configuration.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Red Hat Data Grid 8 Product | all versions | No fix yet |
| Red Hat JBoss Enterprise Application Platform Expansion Pack Product | all versions | No fix yet |
| Red Hat Single Sign-On 7 Product | all versions | No fix yet |
| Red Hat build of Keycloak 26.6.7 Product | all versions | No fix yet |
| all versions | No fix yet | |
| all versions | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-639
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 16 | Red Hat PipeWire: code execution | High8.8 | No fix yet |
| Jul 16 | Red Hat Keycloak.: improper access control | High8.1 | 26.5.3 |
| Jul 16 | Red Hat Feast Feature Server: denial of service | High7.5 | 0.59.0 |
| Jul 16 | Red Hat libsolv: stack buffer overflow | High7.5 | 0.7.38 |
| Jul 15 | Red Hat AAP Gateway Envoy proxy configuration: authentication bypass by spoofing | High8.2 | No fix yet |
| Jul 15 | Red Hat samba: denial of service | Medium6.1 | No fix yet |