User Creation Flaw in Keycloak for Fine-Grained Admin Permissions V2
CVE-2026-18571
6.6MEDIUM
What is CVE-2026-18571?
A security vulnerability has been identified in Keycloak's user creation process when Fine-Grained Admin Permissions V2 is activated. This flaw permits a sub-administrator, who possesses the ability to create users, to assign those users to any group indiscriminately. This capability allows sub-administrators to place users into groups they are not authorized to manage, consequently posing a risk of unauthorized access to sensitive data or higher privilege levels for those unauthorized users.
References
CVSS V3.1
Score:
6.6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank robinho11842 for reporting this issue.