User Creation Flaw in Keycloak for Fine-Grained Admin Permissions V2
CVE-2026-18571

6.6MEDIUM

What is CVE-2026-18571?

A security vulnerability has been identified in Keycloak's user creation process when Fine-Grained Admin Permissions V2 is activated. This flaw permits a sub-administrator, who possesses the ability to create users, to assign those users to any group indiscriminately. This capability allows sub-administrators to place users into groups they are not authorized to manage, consequently posing a risk of unauthorized access to sensitive data or higher privilege levels for those unauthorized users.

References

CVSS V3.1

Score:
6.6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank robinho11842 for reporting this issue.
.