REDHAT-BUG-2496878: Medium severity Keycloak Fine-Grained Admin Permissions v2 (FGAP v2) vulnerability

Published Jul 3, 2026
·
Updated

A flaw was found in Keycloak's Fine-Grained Admin Permissions v2 (FGAP v2) implementation. When FGAP v2 is enabled, the role groups endpoints (GET /admin/realms/{realm}/clients/{clientUuid}/roles/{roleName}/groups and GET /admin/realms/{realm}/roles/{roleName}/groups) fail to correctly enforce per-group view permissions. The RoleContainerResource.getGroupsInRole() method only verifies that the caller has permission to view the role itself (auth.roles().requireView(roleContainer)). It then returns representations for all groups mapped to that role without verifying if the caller has permission to view each individual group (auth.groups().canView(group)). This allows a delegated administrator with role view access to enumerate hidden groups and retrieve their metadata, including names, paths, and custom attributes, even if direct access to those groups is correctly denied with a 403 Forbidden error.

Affected Software

1 affected component
Keycloak Fine-Grained Admin Permissions v2 (FGAP v2)

Event History

Jul 3, 2026
Data Sourced
via Red Hat·02:48 PM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

What is the severity of REDHAT-BUG-2496878?

The severity of REDHAT-BUG-2496878 is medium, rated at 4.

2

How do I fix REDHAT-BUG-2496878?

To fix REDHAT-BUG-2496878, ensure that Fine-Grained Admin Permissions v2 is properly configured and user roles are accurately enforced.

3

What product is affected by REDHAT-BUG-2496878?

The affected product for REDHAT-BUG-2496878 is Keycloak Fine-Grained Admin Permissions v2 (FGAP v2).

4

What is the description of REDHAT-BUG-2496878?

REDHAT-BUG-2496878 describes a flaw in Keycloak's FGAP v2 implementation that fails to correctly enforce role group permissions.

5

When was REDHAT-BUG-2496878 published?

REDHAT-BUG-2496878 was published on July 3, 2026.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203