Medium severity4.3NVD Advisory· Published Jul 16, 2026· Updated Aug 9, 2026
CVE-2026-15945
CVE-2026-15945
Description
A flaw was found in the group search functionality of the Keycloak server's administrative API. When Fine-Grained Admin Permissions (FGAP) v2 is enabled, a delegated administrator can bypass access restrictions to view parent groups they are not authorized to see. By searching for a child group they have permission to view, the system incorrectly returns the full details of the parent group in the response, leading to the disclosure of sensitive group attributes and configuration.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6- cpe:2.3:a:redhat:build_of_keycloak:-:*:*:*:-:*:*:*
- cpe:2.3:a:redhat:jboss_enterprise_application_platform_expansion_pack:-:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:single_sign-on:7.0:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
2- access.redhat.com/security/cve/CVE-2026-15945nvdVendor Advisory
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingVendor Advisory
News mentions
1- Keycloak Services: Nine Moderate Vulnerabilities Disclosed in Authorization and Session ManagementVypr Intelligence · Jul 17, 2026