Vulnerability Description
A flaw was found in the Fine-Grained Admin Permissions (FGAP) v2 implementation within Keycloak's administrative services. When FGAP v2 is enabled, the system fails to properly filter child groups based on the caller's specific permissions when requested through a parent group. This allows a delegated administrator to view details of child groups they are not authorized to access directly, including group names, paths, and custom attributes.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Build Of Keycloak | >= 26.4, < 26.4.14 |
Related Weaknesses (CWE)
References
- https://access.redhat.com/errata/RHSA-2026:50846Vendor Advisory
- https://access.redhat.com/errata/RHSA-2026:50847Vendor Advisory
- https://access.redhat.com/errata/RHSA-2026:50848Vendor Advisory
- https://access.redhat.com/errata/RHSA-2026:50849Vendor Advisory
- https://access.redhat.com/security/cve/CVE-2026-14615Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2496891Issue TrackingVendor Advisory
FAQ
What is CVE-2026-14615?
CVE-2026-14615 is a vulnerability with a CVSS score of 4.3 (MEDIUM). A flaw was found in the Fine-Grained Admin Permissions (FGAP) v2 implementation within Keycloak's administrative services. When FGAP v2 is enabled, the system fails to properly filter child groups bas...
How severe is CVE-2026-14615?
CVE-2026-14615 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-14615?
Check the references section above for vendor advisories and patch information. Affected products include: Redhat Build Of Keycloak.