Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3943 articles · 197513 vulns · 37/41 feeds (7d)
← Back to list
4.3
CVE-2026-14613EXPLOITEDPATCHED
red hat · build_of_keycloak

Keycloak-services: keycloak-services: keycloak: fgap v2 role groups endpoint discloses hidden group metadata without group view permission

Description

A vulnerability was discovered in Keycloak's administrative interface that allows certain administrators to see information about groups they shouldn't have access to. When the new Fine-Grained Admin Permissions (FGAP v2) are turned on, an administrator who is allowed to see a specific "role" can also see a list of all groups assigned to that role. The system fails to check if the administrator has permission to see those specific groups. This could allow a restricted administrator to discover "hidden" groups and see their details, such as internal names and custom settings, which might contain sensitive deployment information.

Affected Products

VendorProductVersions
red hatbuild_of_keycloak—

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
open sourceopen source keycloakcert_advisory90%

References

  • https://access.redhat.com/errata/RHSA-2026:56523(vendor-advisory, x_refsource_REDHAT)
  • https://access.redhat.com/errata/RHSA-2026:56524(vendor-advisory, x_refsource_REDHAT)
  • https://access.redhat.com/security/cve/CVE-2026-14613(vdb-entry, x_refsource_REDHAT)
  • https://bugzilla.redhat.com/show_bug.cgi?id=2496878(issue-tracking, x_refsource_REDHAT)

Related News (3 articles)

Tier D
Heise Security19h ago
Zugriffsverwaltung Keycloak: Kontoübernahme durch Passwort-Rücksetzfunktion
→ No new info (linked only)
Tier B
BSI Advisories50d ago
[NEU] [UNGEPATCHT] [mittel] Keycloak: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
VulDB53d ago
CVE-2026-14613 | Keycloak on Red Hat permission
→ No new info (linked only)
CVSS 3.14.3 NONE
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
26.6-1226.6.6-1
PublishedJul 3, 2026
Last enriched53d agov2
Trending Score50
Source articles3
Independent3
Info Completeness5/14
Missing: versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-18963
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
Trending: 60
NONECVE-2026-78367EXP
Rpm: rpmbuild gettarspec() crafted tar member name → macro injection
Trending: 58
NONECVE-2026-78465EXP
Gimp: integer overflow in pcx loader (planes=4) leads to heap overflow on 32-bit
Trending: 58
HIGHCVE-2026-79655EXP
Sos: sos: path traversal in sos clean tar extraction via unvalidated symlink/hardlink targets leads to arbitrary file write
Trending: 56
CRITICALCVE-2026-19685EXP
Networkmanager: networkmanager: 802-1x ca-path and phase2-ca-path bypass private_user restriction, allowing wpa-enterprise server validation bypass (incomplete fix for cve-2025-9615)
Trending: 53

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 3, 2026
Discovered by ZDM
Jul 3, 2026
Updated: severity, activelyExploited
Jul 3, 2026
Actively Exploited
Aug 19, 2026
Patch Available
Aug 19, 2026

Version History

v2
Last enriched 53d ago
v2Tier C53d ago

Updated severity to CRITICAL and marked exploit availability as false.

severityactivelyExploited
via VulDB
v153d ago

Initial creation