CVE-2026-15945
Last modified
CVE-2026-15945 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. A flaw was found in the group search functionality of the Keycloak server's administrative API. When Fine-Grained Admin Permissions (FGAP) v2 is enabled, a delegated administrator can bypass access restrictions to view parent groups they are not authorized to see. EPSS estimates a 0.19% chance of exploitation in the next 30 days.
Description
A flaw was found in the group search functionality of the Keycloak server's administrative API. When Fine-Grained Admin Permissions (FGAP) v2 is enabled, a delegated administrator can bypass access restrictions to view parent groups they are not authorized to see. By searching for a child group they have permission to view, the system incorrectly returns the full details of the parent group in the response, leading to the disclosure of sensitive group attributes and configuration.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat Build of Keycloak | All versions |
| Red Hat | Red Hat Data Grid 8 | All versions |
| Red Hat | Red Hat JBoss Enterprise Application Platform Expansion Pack | All versions |
| Red Hat | Red Hat Single Sign-On 7 | All versions |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-15945?
How severe is CVE-2026-15945?
How do I fix CVE-2026-15945?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-15927A flaw was found in Red Hat Quay's repository-level mirror c…6.8
- CVE-2026-15928XMLRPC-C Library versions 1.07 through 1.67.01 are vulnerabl…8.2
- CVE-2026-15929Improper neutralization of special elements used in an SQL c…7.1
- CVE-2026-1593A weakness has been identified in itsourcecode Society Manag…9.8
- CVE-2026-1594A security vulnerability has been detected in itsourcecode S…9.8
- CVE-2026-15943A flaw was found in the Keycloak keycloak-services component…5.5
- CVE-2026-1595A vulnerability was detected in itsourcecode Society Managem…9.8
- CVE-2026-15957Smithy-RS is a Rust code generation and runtime framework th…8.7
- CVE-2026-1596A flaw has been found in D-Link DWR-M961 1.1.47. This vulner…8.8
- CVE-2026-15962The Fluent Forms Pro Add On Pack plugin for WordPress is vul…8.8
- CVE-2026-15966Permissive cross-domain security policy with untrusted domai…9.8
- CVE-2026-15967Insufficient session expiration vulnerability in Progress MO…9.8
Are you affected by CVE-2026-15945?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
