Vulnerability Description
A vulnerability was discovered in Keycloak's administrative interface that allows certain administrators to see information about groups they shouldn't have access to. When the new Fine-Grained Admin Permissions (FGAP v2) are turned on, an administrator who is allowed to see a specific "role" can also see a list of all groups assigned to that role. The system fails to check if the administrator has permission to see those specific groups. This could allow a restricted administrator to discover "hidden" groups and see their details, such as internal names and custom settings, which might contain sensitive deployment information.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Build Of Keycloak | - |
Related Weaknesses (CWE)
References
- https://access.redhat.com/errata/RHSA-2026:56523
- https://access.redhat.com/errata/RHSA-2026:56524
- https://access.redhat.com/security/cve/CVE-2026-14613Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2496878Issue TrackingVendor Advisory
FAQ
What is CVE-2026-14613?
CVE-2026-14613 is a vulnerability with a CVSS score of 4.3 (MEDIUM). A vulnerability was discovered in Keycloak's administrative interface that allows certain administrators to see information about groups they shouldn't have access to. When the new Fine-Grained Admin ...
How severe is CVE-2026-14613?
CVE-2026-14613 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-14613?
Check the references section above for vendor advisories and patch information. Affected products include: Redhat Build Of Keycloak.