CVE-2026-15945: Keycloak-services: keycloak-services: group hierarchy search discloses hidden parent groups under fgap v2

Published Jul 16, 2026
·
Updated

A flaw was found in the group search functionality of the Keycloak server's administrative API. When Fine-Grained Admin Permissions (FGAP) v2 is enabled, a delegated administrator can bypass access restrictions to view parent groups they are not authorized to see. By searching for a child group they have permission to view, the system incorrectly returns the full details of the parent group in the response, leading to the disclosure of sensitive group attributes and configuration.

Other sources

An information disclosure vulnerability exists in keycloak-services when Fine-Grained Admin Permissions (FGAP) v2 is enabled. The issue resides in the GET /admin/realms/{realm}/groups endpoint when the search parameter is used with briefRepresentation=false. The root cause is improper authorization filtering during the construction of the group hierarchy in the search results. While a delegated admin may be explicitly denied direct access to a parent group (resulting in a 403 Forbidden on direct GET requests), the search mechanism fails to redact the parent group's details when it is returned as part of the hierarchy for a visible child group. Exploitation Conditions: FGAP v2 must be enabled.

The attacker must have an account with query-groups permissions.

The attacker must have Groups:view permissions on at least one child group within a restricted parent group.

Concrete Impact: An attacker can disclose the following information for unauthorized parent groups: Internal UUIDs and group names.

Custom group attributes (which may contain sensitive metadata).

Role mappings associated with the parent group.

Red Hat

Affected Software

5 affected components
Keycloak=
redhat Build Of Keycloak
redhat Data Grid=8.0
redhat Jboss Enterprise Application Platform Expansion Pack
redhat Single Sign-on=7.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Mitigate the information disclosure by disabling Fine-Grained Admin Permissions (FGAP) v2, since the vulnerability exists in keycloak-services when FGAP v2 is enabled (group hierarchy search discloses hidden parent groups).

    Keycloak server administrative API (keycloak-services) Fine-Grained Admin Permissions (FGAP) v2 = disabled
  2. Configuration

    Avoid using the groups search with briefRepresentation=false on the GET /admin/realms/{realm}/groups endpoint, since the issue resides in this endpoint when the search parameter is used with briefRepresentation=false and results fail to redact hidden parent group details.

    Keycloak server administrative API (GET /admin/realms/{realm}/groups) search parameter + briefRepresentation=false = avoid briefRepresentation=false when using search

Event History

Jul 16, 2026
Data Sourced
via Red Hat·12:27 PM
DescriptionSeverityAffected Software
CVE Published
via MITRE·05:36 PM
Data Sourced
via MITRE·05:36 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:16 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-15945?

The severity of CVE-2026-15945 is medium with a score of 4.3.

2

How do I fix CVE-2026-15945?

To fix CVE-2026-15945, ensure that Fine-Grained Admin Permissions (FGAP) v2 is properly configured to restrict group visibility.

3

What impact does CVE-2026-15945 have on Keycloak?

CVE-2026-15945 allows delegated administrators to see hidden parent groups, violating access restrictions.

4

Who is affected by CVE-2026-15945?

CVE-2026-15945 affects Keycloak users utilizing Fine-Grained Admin Permissions (FGAP) v2.

5

What version of Keycloak is impacted by CVE-2026-15945?

CVE-2026-15945 impacts the Keycloak server when FGAP v2 is enabled.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203