Information Disclosure Vulnerability in Keycloak Admin REST API by Red Hat
CVE-2025-14082
Key Information:
- Vendor
Red Hat
- Vendor
- CVE Published:
- 10 December 2025
What is CVE-2025-14082?
A vulnerability exists in the Keycloak Admin REST API that compromises the security of sensitive role metadata. The flaw arises from inadequate authorization checks on the /admin/realms/{realm}/roles endpoint, allowing unauthorized users to access potentially sensitive information. This issue underscores the necessity for robust authentication mechanisms and careful validation within API endpoints to protect against unauthorized data exposure.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Red Hat build of Keycloak 26.4 26.4.11-1
Red Hat build of Keycloak 26.4 26.4-14
Red Hat build of Keycloak 26.4 26.4-14
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved