CVE-2025-14082: Keycloak-services: keycloak admin rest api: improper access control leads to sensitive role metadata information disclosure

Published Dec 5, 2025
·
Updated

A flaw was found in Keycloak Admin REST (Representational State Transfer) API. This vulnerability allows information disclosure of sensitive role metadata via insufficient authorization checks on the /admin/realms/{realm}/roles endpoint.

Other sources

Improper Access Control vulnerability in the Keycloak Admin REST API. A user possessing only the built-in rolequery-groups permission can retrieve the complete list of realm roles, including sensitive administrator-created roles and internal metadata. Although the user cannot access full role details or modify configurations, this unintended exposure of role names, IDs, composite status, and container identifiers stems from insufficient authorization checks on the /admin/realms/{realm}/roles endpoint. A remote authenticated attacker with high-privileged (but restricted) access can leverage this information disclosure to map privilege structures and plan targeted privilege-escalation attempts, affecting the confidentiality of Keycloak deployments.

Red Hat

Affected Software

2 affected components
Red Hat Keycloak
maven/org.keycloak:keycloak-services<=26.4.7

Event History

Dec 5, 2025
Data Sourced
via Red Hat·05:31 AM
DescriptionSeverityAffected Software
Dec 10, 2025
CVE Published
via MITRE·09:04 AM
Data Sourced
via MITRE·09:04 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeakness
Advisory Published
via GitHub·09:30 AM
Data Sourced
via GitHub·09:30 AM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-14082?

CVE-2025-14082 has been classified as a medium severity vulnerability due to its potential for information disclosure.

2

How do I fix CVE-2025-14082?

To fix CVE-2025-14082, ensure that proper authorization checks are implemented on the /admin/realms/{realm}/roles endpoint.

3

What systems are affected by CVE-2025-14082?

CVE-2025-14082 affects Red Hat Keycloak installations that utilize the Admin REST API.

4

What type of vulnerability is CVE-2025-14082?

CVE-2025-14082 is an information disclosure vulnerability resulting from insufficient authorization checks.

5

Can CVE-2025-14082 lead to unauthorized access?

Yes, CVE-2025-14082 can potentially lead to unauthorized access to sensitive role metadata.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203