CVE-2026-14614: Keycloak-services: keycloak-services: fgap v2 client scope assignment bypass via clientresource

Published Jul 3, 2026
·
Updated

A flaw was found in the ClientResource component of Keycloak's admin services when Fine-Grained Admin Permissions (FGAP) v2 is enabled. This issue allows a delegated administrator, who should only have limited control over specific clients, to attach or remove hidden client scopes that they are not authorized to see or manage. As a result, an attacker could inject unauthorized data or permissions into the security tokens issued to end-users, potentially tricking other applications into granting higher levels of access than intended.

Other sources

A write-path authorization bypass vulnerability exists in the ClientResource.addDefaultClientScope() and related endpoints in Keycloak when adminPermissionsEnabled is set to true (FGAP v2). The flaw stems from insufficient permission validation: the code only verifies that the caller has manage permissions on the target client but fails to check if the caller has any permissions (such as view or map) on the client scope being attached. An attacker with a delegated admin role (Clients:view and Clients:manage on at least one client) can exploit this by discovering the UUID of a "hidden" client scope (one they are otherwise restricted from accessing). By calling the client scope assignment endpoints, the attacker can successfully link these hidden scopes to their managed client. Concrete Impact: Unauthorized Claim Injection: Attacker can inject claims from restricted client scopes into end-user access tokens.

Authorization Bypass in Relying Apps: Applications relying on Keycloak token claims for internal authorization decisions may grant unauthorized access based on the injected claims.

Data Exposure: If the hidden scope contains sensitive hardcoded claims or mappers, these are exposed to the end-user and the relying application.

Red Hat

Affected Software

3 affected components
Keycloak ClientResource (admin services)=FGAP v2 (adminPermissionsEnabled=true)
redhat Build Of Keycloak>=26.4<26.4.14
redhat Build Of Keycloak>=26.6<26.6.5

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    In Keycloak admin services, disable Fine-Grained Admin Permissions (FGAP) v2 by setting adminPermissionsEnabled to false to prevent the write-path authorization bypass in ClientResource.addDefaultClientScope() and related endpoints.

    Keycloak admin services (ClientResource; FGAP v2) adminPermissionsEnabled = false
  2. Compensating control

    Mitigate the impact by preventing delegated admins (who only have Clients:view and Clients:manage on selected clients) from being able to call client scope assignment endpoints that could attach hidden client scopes; restrict access to those endpoints to trusted admins only (e.g., via network/API access control or other external access restrictions).

Event History

Jul 3, 2026
Data Sourced
via Red Hat·03:13 PM
DescriptionSeverityAffected Software
CVE Published
via MITRE·03:33 PM
Data Sourced
via MITRE·03:33 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2026-14614?

The severity of CVE-2026-14614 is rated as medium with a score of 5.4.

2

How do I fix CVE-2026-14614?

To fix CVE-2026-14614, ensure that Fine-Grained Admin Permissions (FGAP) v2 is correctly configured and review delegated administrations for potential unauthorized access.

3

What components are affected by CVE-2026-14614?

CVE-2026-14614 affects the Keycloak ClientResource component within the admin services.

4

Who is at risk from CVE-2026-14614?

Delegated administrators with limited control may bypass restrictions due to CVE-2026-14614, risking unauthorized access to hidden client scopes.

5

When was CVE-2026-14614 published?

CVE-2026-14614 was published on July 3, 2026.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203