SEPTEMBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-15945

MEDIUM · CVSS 4.3 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-07-16 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

A vulnerability exists in the Keycloak server's administrative API, specifically in the group search functionality when Fine-Grained Admin Permissions v2 is enabled. This flaw allows delegated administrators to bypass access restrictions, potentially exposing sensitive attributes and configurations of parent groups by searching for child groups they are authorized to view. Organizations using Keycloak with FGAP v2 enabled should prioritize addressing this issue to mitigate the risk of unauthorized information disclosure.

CVE
CVE-2026-15945
Severity
MEDIUM
CVSS
4.3
EPSS
0.18%

Original NVD Description

A flaw was found in the group search functionality of the Keycloak server's administrative API. When Fine-Grained Admin Permissions (FGAP) v2 is enabled, a delegated administrator can bypass access restrictions to view parent groups they are not authorized to see. By searching for a child group they have permission to view, the system incorrectly returns the full details of the parent group in the response, leading to the disclosure of sensitive group attributes and configuration.

Related CVEs

Other vulnerabilities affecting the same vendor(s)