CVE-2026-14615: Red Hat Build Of Keycloak

Low severity, CVSS 2.7. EPSS: 0.4% chance of exploitation in the next 30 days.

A flaw was found in the Fine-Grained Admin Permissions (FGAP) v2 implementation within Keycloak's administrative services. When FGAP v2 is enabled, the system fails to properly filter child groups based on the caller's specific permissions when requested through a parent group. This allows a delegated administrator to view details of child groups they are not authorized to access directly, including group names, paths, and custom attributes.

Affected products

  • Red Hat Build Of Keycloak: from 26.4, before 26.4.14 (fixed in 26.4.14); from 26.6, before 26.6.5 (fixed in 26.6.5)

Published 2026-07-03. Last modified 2026-08-11.