CVE-2026-15945
Last modified
CVE-2026-15945 is a low-severity vulnerability rated 2.7/10 on the CVSS scale. A flaw was found in the group search functionality of the Keycloak server's administrative API. When Fine-Grained Admin Permissions (FGAP) v2 is enabled, a delegated administrator can bypass access restrictions to view parent groups they are not authorized to see. EPSS estimates a 0.26% chance of exploitation in the next 30 days.
Description
A flaw was found in the group search functionality of the Keycloak server's administrative API. When Fine-Grained Admin Permissions (FGAP) v2 is enabled, a delegated administrator can bypass access restrictions to view parent groups they are not authorized to see. By searching for a child group they have permission to view, the system incorrectly returns the full details of the parent group in the response, leading to the disclosure of sensitive group attributes and configuration.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Build Of Keycloak | All versions |
| Redhat | Data Grid | 8.0 |
| Redhat | Jboss Enterprise Application Platform Expansion Pack | All versions |
| Redhat | Single Sign-On | 7.0 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2026-15945?
How severe is CVE-2026-15945?
How do I fix CVE-2026-15945?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-15933OptimiDoc Server (On-Premise) stores credentials for externa…6.9
- CVE-2026-15937Improper certificate validation in Checkmk <2.5.0p10 allows …5.3
- CVE-2026-15939The Simple Restrict WordPress plugin before 1.2.9 does not e…2.7
- CVE-2026-1594A security vulnerability has been detected in itsourcecode S…9.8
- CVE-2026-15941The plugin provides an Admin Search page that allows users w…6.5
- CVE-2026-15943A flaw was found in the Keycloak keycloak-services component…5.5
- CVE-2026-15946The Search Atlas SEO – Premier SEO Plugin for One-Click WP P…4.3
- CVE-2026-15947The Metasync plugin for WordPress is vulnerable to unauthori…4.3
- CVE-2026-15948The Hydra Booking — Appointment Scheduling & Booking Calenda…6.4
- CVE-2026-1595A vulnerability was detected in itsourcecode Society Managem…9.8
- CVE-2026-15950The Cozy Blocks – Page Builder for Gutenberg Editor & FSE wi…6.4
- CVE-2026-15951The Icegram Mailer plugin for WordPress is vulnerable to SQL…4.9
Are you affected by CVE-2026-15945?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
