keycloak-services: keycloak-services: Group hierarchy search discloses hidden parent groups under FGAP v2

cve CVE-2026-15945 2 sources, 2 claims · Watch

Red Hat writes:
keycloak-services: keycloak-services: Group hierarchy search discloses hidden parent groups under FGAP v2 the claim
Severity they disagree
LOW NVD
moderate Red Hat
CVSS they disagree
2.7 NVD
4.3 Red Hat
Vendor
Red Hat NVD
Product
Red Hat build of Keycloak 26.6 NVD
CWE
CWE-639 NVD
CWE-639 Red Hat

How far exploitation has got

  1. No public code known
  2. Proof of concept
  3. Proof of concept, verified
  4. A Metasploit module
  5. Exploited in the wild
  6. Used in ransomware campaigns

Why the CVSS differs

MetricNVDRed Hat
Attack vector AVnetwork Nnetwork N
Attack complexity AClow Llow L
Privileges required PRhigh Hlow L
User interaction UInone Nnone N
Scope Sunchanged Uunchanged U
Confidentiality Clow Llow L
Integrity Inone Nnone N
Availability Anone Nnone N

Each source scores the same vulnerability from what it judges the attack to need. The rows marked are where they judge it differently.

Timeline

2026-07-14first spoke of it: keycloak-services: keycloak-services: Group hierarchy search discloses hidden parent groups under FGAP v2Red Hat
2026-07-16first spoke of it: A flaw was found in the group search functionality of the Keycloak server's administrative API. When Fine-Grained Admin Permissions (FGAP) v2 is enabled, a delegated administrator can bypass access restrictions to view parent groups they are not authorized to see. By searching for a child group they have permission to view, the system incorrectly returns the full details of the parent group in the response, leading to the disclosure of sensitive group attributes and configuration.NVD

What it is to other things

affectsredhat/build_of_keycloak
NVD
affectsredhat/data_grid
NVD
affectsredhat/jboss_enterprise_application_platform_expansion_pack
NVD
affectsredhat/single_sign-on
NVD
made_byredhat
NVD

In words only, so not counted until a person confirms one:

made_byred_hat
NVD says “Red Hat”
affectsred_hat/red_hat_build_of_keycloak_26_6
NVD says “Red Hat · Red Hat build of Keycloak 26.6”
Every value, with what each source said and its receipt
PropertySourceSaidMeans here
Automatable
automatable
NVDno
At least one of those steps needs a person.
receipt
Source
NVD
Its words
no
Read by
field:cve.metrics.ssvcV203[].ssvcData.options[].automatable
Said since
2026-10-06 12:29 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:29 UTCno
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "collectionURL": "https://catalog.redhat.com/software/containers/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.6::el9"
            ],
            "defaultStatus": "affected",
            "packageName": "rhbk/keycloak-operator-bundle",
            "product": "Red Hat build of Keycloak 26.6",
            "vendor": "Red Hat",
            "versions": [
              {
                "lessThan": "*",
                "status": "unaffected",
                "version": "26.6.7-3",
                "versionType": "rpm"
              }
            ]
          },
          {
            "collectionURL": "https://catalog.redhat.com/software/containers/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.6::el9"
            ],
            "defaultStatus": "affected",
            "packageName": "rhbk/keycloak-rhel9",
            "product": "Red Hat build of Keycloak 26.6",
            "vendor": "Red Hat",
            "versions": [
              {
                "lessThan": "*",
                "status": "unaffected",
                "version": "26.6-20",
                "versionType": "rpm"
              }
            ]
          },
          {
            "collectionURL": "https://catalog.redhat.com/software/containers/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.6::el9"
            ],
            "defaultStatus": "affected",
            "packageName": "rhbk/keycloak-rhel9-operator",
            "product": "Red Hat build of Keycloak 26.6",
            "vendor": "Red Hat",
            "versions": [
              {
                "lessThan": "*",
                "status": "unaffected",
                "version": "26.6-20",
                "versionType": "rpm"
              }
            ]
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.6::el9"
            ],
            "defaultStatus": "unaffected",
            "packageName": "keycloak-services",
            "product": "Red Hat build of Keycloak 26.6.7",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.6::el9"
            ],
            "defaultStatus": "unaffected",
            "packageName": "rhbk-keycloak-rhel9/rhbk-keycloak-rhel9",
            "product": "Red Hat build of Keycloak 26.6.7",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.6::el9"
            ],
            "defaultStatus": "unaffected",
            "packageName": "rhbk-openshift-rhel9/rhbk-openshift-rhel9",
            "product": "Red Hat build of Keycloak 26.6.7",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:jboss_data_grid:8"
            ],
            "defaultStatus": "affected",
            "packageName": "keycloak-services",
            "product": "Red Hat Data Grid 8",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://access.redhat.com/jbossnetwork/restricted/listSoftware.html",
            "cpes": [
              "cpe:/a:redhat:jbosseapxp"
            ],
            "defaultStatus": "affected",
            "packageName": "keycloak-services",
            "product": "Red Hat JBoss Enterprise Application Platform Expansion Pack",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:red_hat_single_sign_on:7"
            ],
            "defaultStatus": "affected",
            "packageName": "keycloak-services",
            "product": "Red Hat Single Sign-On 7",
            "vendor": "Red Hat"
          }
        ],
        "source": "secalert@redhat.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:redhat:build_of_keycloak:-:*:*:*:-:*:*:*",
                "matchCriteriaId": "E5C930CB-4EAD-497B-A44B-D880F2A1F85B",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:redhat:data_grid:8.0:*:*:*:*:*:*:*",
                "matchCriteriaId": "7095200A-4DAC-4433-99E8-86CA88E1E4D4",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:redhat:jboss_enterprise_application_platform_expansion_pack:-:*:*:*:*:*:*:*",
                "matchCriteriaId": "0A24CBFB-4900-47A5-88D2-A44C929603DC",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:redhat:single_sign-on:7.0:*:*:*:*:*:*:*",
                "matchCriteriaId": "9EFEC7CA-8DDA-48A6-A7B6-1F1D14792890",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A flaw was found in the group search functionality of the Keycloak server's administrative API. When Fine-Grained Admin Permissions (FGAP) v2 is enabled, a delegated administrator can bypass access restrictions to view parent groups they are not authorized to see. By searching for a child group they have permission to view, the system incorrectly returns the full details of the parent group in the response, leading to the disclosure of sensitive group attributes and configuration."
      }
    ],
    "id": "CVE-2026-15945",
    "lastModified": "2026-09-16T19:17:06.900",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 4.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 1.4,
          "source": "secalert@redhat.com",
          "type": "Secondary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 2.7,
            "baseSeverity": "LOW",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "HIGH",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 1.2,
          "impactScore": 1.4,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-15945",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-07-17T13:59:59.366659Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-07-16T18:16:42.693",
    "references": [
      {
        "source": "secalert@redhat.com",
        "url": "https://access.redhat.com/errata/RHSA-2026:68277"
      },
      {
        "source": "secalert@redhat.com",
        "url": "https://access.redhat.com/errata/RHSA-2026:68278"
      },
      {
        "source": "secalert@redhat.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://access.redhat.com/security/cve/CVE-2026-15945"
      },
      {
        "source": "secalert@redhat.com",
        "tags": [
          "Issue Tracking",
          "Vendor Advisory"
        ],
        "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2501302"
      }
    ],
    "sourceIdentifier": "secalert@redhat.com",
    "vulnStatus": "Modified",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-639"
          }
        ],
        "source": "secalert@redhat.com",
        "type": "Secondary"
      }
    ]
  }
}
—
CVSS
cvss
conflict
NVD2.7
receipt
Source
NVD
Its words
2.7
Read by
field:cve.metrics.cvssMetricV31[type=Primary].cvssData.baseScore || field:cve.metrics.cvssMetricV31[].cvssData.baseScore
Said since
2026-10-06 11:32 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 11:32 UTC2.7
2026-09-29 09:45 UTC4.3
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "collectionURL": "https://catalog.redhat.com/software/containers/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.6::el9"
            ],
            "defaultStatus": "affected",
            "packageName": "rhbk/keycloak-operator-bundle",
            "product": "Red Hat build of Keycloak 26.6",
            "vendor": "Red Hat",
            "versions": [
              {
                "lessThan": "*",
                "status": "unaffected",
                "version": "26.6.7-3",
                "versionType": "rpm"
              }
            ]
          },
          {
            "collectionURL": "https://catalog.redhat.com/software/containers/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.6::el9"
            ],
            "defaultStatus": "affected",
            "packageName": "rhbk/keycloak-rhel9",
            "product": "Red Hat build of Keycloak 26.6",
            "vendor": "Red Hat",
            "versions": [
              {
                "lessThan": "*",
                "status": "unaffected",
                "version": "26.6-20",
                "versionType": "rpm"
              }
            ]
          },
          {
            "collectionURL": "https://catalog.redhat.com/software/containers/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.6::el9"
            ],
            "defaultStatus": "affected",
            "packageName": "rhbk/keycloak-rhel9-operator",
            "product": "Red Hat build of Keycloak 26.6",
            "vendor": "Red Hat",
            "versions": [
              {
                "lessThan": "*",
                "status": "unaffected",
                "version": "26.6-20",
                "versionType": "rpm"
              }
            ]
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.6::el9"
            ],
            "defaultStatus": "unaffected",
            "packageName": "keycloak-services",
            "product": "Red Hat build of Keycloak 26.6.7",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.6::el9"
            ],
            "defaultStatus": "unaffected",
            "packageName": "rhbk-keycloak-rhel9/rhbk-keycloak-rhel9",
            "product": "Red Hat build of Keycloak 26.6.7",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.6::el9"
            ],
            "defaultStatus": "unaffected",
            "packageName": "rhbk-openshift-rhel9/rhbk-openshift-rhel9",
            "product": "Red Hat build of Keycloak 26.6.7",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:jboss_data_grid:8"
            ],
            "defaultStatus": "affected",
            "packageName": "keycloak-services",
            "product": "Red Hat Data Grid 8",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://access.redhat.com/jbossnetwork/restricted/listSoftware.html",
            "cpes": [
              "cpe:/a:redhat:jbosseapxp"
            ],
            "defaultStatus": "affected",
            "packageName": "keycloak-services",
            "product": "Red Hat JBoss Enterprise Application Platform Expansion Pack",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:red_hat_single_sign_on:7"
            ],
            "defaultStatus": "affected",
            "packageName": "keycloak-services",
            "product": "Red Hat Single Sign-On 7",
            "vendor": "Red Hat"
          }
        ],
        "source": "secalert@redhat.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:redhat:build_of_keycloak:-:*:*:*:-:*:*:*",
                "matchCriteriaId": "E5C930CB-4EAD-497B-A44B-D880F2A1F85B",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:redhat:data_grid:8.0:*:*:*:*:*:*:*",
                "matchCriteriaId": "7095200A-4DAC-4433-99E8-86CA88E1E4D4",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:redhat:jboss_enterprise_application_platform_expansion_pack:-:*:*:*:*:*:*:*",
                "matchCriteriaId": "0A24CBFB-4900-47A5-88D2-A44C929603DC",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:redhat:single_sign-on:7.0:*:*:*:*:*:*:*",
                "matchCriteriaId": "9EFEC7CA-8DDA-48A6-A7B6-1F1D14792890",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A flaw was found in the group search functionality of the Keycloak server's administrative API. When Fine-Grained Admin Permissions (FGAP) v2 is enabled, a delegated administrator can bypass access restrictions to view parent groups they are not authorized to see. By searching for a child group they have permission to view, the system incorrectly returns the full details of the parent group in the response, leading to the disclosure of sensitive group attributes and configuration."
      }
    ],
    "id": "CVE-2026-15945",
    "lastModified": "2026-09-16T19:17:06.900",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 4.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 1.4,
          "source": "secalert@redhat.com",
          "type": "Secondary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 2.7,
            "baseSeverity": "LOW",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "HIGH",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 1.2,
          "impactScore": 1.4,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-15945",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-07-17T13:59:59.366659Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-07-16T18:16:42.693",
    "references": [
      {
        "source": "secalert@redhat.com",
        "url": "https://access.redhat.com/errata/RHSA-2026:68277"
      },
      {
        "source": "secalert@redhat.com",
        "url": "https://access.redhat.com/errata/RHSA-2026:68278"
      },
      {
        "source": "secalert@redhat.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://access.redhat.com/security/cve/CVE-2026-15945"
      },
      {
        "source": "secalert@redhat.com",
        "tags": [
          "Issue Tracking",
          "Vendor Advisory"
        ],
        "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2501302"
      }
    ],
    "sourceIdentifier": "secalert@redhat.com",
    "vulnStatus": "Modified",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-639"
          }
        ],
        "source": "secalert@redhat.com",
        "type": "Secondary"
      }
    ]
  }
}
—
CVSS
cvss
conflict
Red Hat4.3
receipt
Source
Red Hat
Its words
4.3
Read by
field:cvss3_score
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-06 13:02 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2026-15945",
  "CWE": "CWE-639",
  "advisories": [
    "RHSA-2026:68277",
    "RHSA-2026:68278"
  ],
  "affected_packages": [
    "rhbk-keycloak-rhel9/rhbk-keycloak-rhel9",
    "rhbk/keycloak-rhel9:26.6-20",
    "keycloak-services",
    "rhbk-openshift-rhel9/rhbk-openshift-rhel9",
    "rhbk/keycloak-rhel9-operator:26.6-20",
    "rhbk/keycloak-operator-bundle:26.6.7-3"
  ],
  "bugzilla": "2501302",
  "bugzilla_description": "keycloak-services: keycloak-services: Group hierarchy search discloses hidden parent groups under FGAP v2",
  "cvss3_score": "4.3",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-07-14T15:31:04Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-15945.json",
  "severity": "moderate"
}
—
CVSS vector
cvss_vector
not compared
NVDCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
receipt
Source
NVD
Its words
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
Read by
field:cve.metrics.cvssMetricV31[type=Primary].cvssData.vectorString || field:cve.metrics.cvssMetricV31[].cvssData.vectorString
Said since
2026-10-06 12:29 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:29 UTCCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "collectionURL": "https://catalog.redhat.com/software/containers/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.6::el9"
            ],
            "defaultStatus": "affected",
            "packageName": "rhbk/keycloak-operator-bundle",
            "product": "Red Hat build of Keycloak 26.6",
            "vendor": "Red Hat",
            "versions": [
              {
                "lessThan": "*",
                "status": "unaffected",
                "version": "26.6.7-3",
                "versionType": "rpm"
              }
            ]
          },
          {
            "collectionURL": "https://catalog.redhat.com/software/containers/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.6::el9"
            ],
            "defaultStatus": "affected",
            "packageName": "rhbk/keycloak-rhel9",
            "product": "Red Hat build of Keycloak 26.6",
            "vendor": "Red Hat",
            "versions": [
              {
                "lessThan": "*",
                "status": "unaffected",
                "version": "26.6-20",
                "versionType": "rpm"
              }
            ]
          },
          {
            "collectionURL": "https://catalog.redhat.com/software/containers/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.6::el9"
            ],
            "defaultStatus": "affected",
            "packageName": "rhbk/keycloak-rhel9-operator",
            "product": "Red Hat build of Keycloak 26.6",
            "vendor": "Red Hat",
            "versions": [
              {
                "lessThan": "*",
                "status": "unaffected",
                "version": "26.6-20",
                "versionType": "rpm"
              }
            ]
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.6::el9"
            ],
            "defaultStatus": "unaffected",
            "packageName": "keycloak-services",
            "product": "Red Hat build of Keycloak 26.6.7",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.6::el9"
            ],
            "defaultStatus": "unaffected",
            "packageName": "rhbk-keycloak-rhel9/rhbk-keycloak-rhel9",
            "product": "Red Hat build of Keycloak 26.6.7",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.6::el9"
            ],
            "defaultStatus": "unaffected",
            "packageName": "rhbk-openshift-rhel9/rhbk-openshift-rhel9",
            "product": "Red Hat build of Keycloak 26.6.7",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:jboss_data_grid:8"
            ],
            "defaultStatus": "affected",
            "packageName": "keycloak-services",
            "product": "Red Hat Data Grid 8",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://access.redhat.com/jbossnetwork/restricted/listSoftware.html",
            "cpes": [
              "cpe:/a:redhat:jbosseapxp"
            ],
            "defaultStatus": "affected",
            "packageName": "keycloak-services",
            "product": "Red Hat JBoss Enterprise Application Platform Expansion Pack",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:red_hat_single_sign_on:7"
            ],
            "defaultStatus": "affected",
            "packageName": "keycloak-services",
            "product": "Red Hat Single Sign-On 7",
            "vendor": "Red Hat"
          }
        ],
        "source": "secalert@redhat.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:redhat:build_of_keycloak:-:*:*:*:-:*:*:*",
                "matchCriteriaId": "E5C930CB-4EAD-497B-A44B-D880F2A1F85B",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:redhat:data_grid:8.0:*:*:*:*:*:*:*",
                "matchCriteriaId": "7095200A-4DAC-4433-99E8-86CA88E1E4D4",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:redhat:jboss_enterprise_application_platform_expansion_pack:-:*:*:*:*:*:*:*",
                "matchCriteriaId": "0A24CBFB-4900-47A5-88D2-A44C929603DC",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:redhat:single_sign-on:7.0:*:*:*:*:*:*:*",
                "matchCriteriaId": "9EFEC7CA-8DDA-48A6-A7B6-1F1D14792890",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A flaw was found in the group search functionality of the Keycloak server's administrative API. When Fine-Grained Admin Permissions (FGAP) v2 is enabled, a delegated administrator can bypass access restrictions to view parent groups they are not authorized to see. By searching for a child group they have permission to view, the system incorrectly returns the full details of the parent group in the response, leading to the disclosure of sensitive group attributes and configuration."
      }
    ],
    "id": "CVE-2026-15945",
    "lastModified": "2026-09-16T19:17:06.900",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 4.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 1.4,
          "source": "secalert@redhat.com",
          "type": "Secondary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 2.7,
            "baseSeverity": "LOW",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "HIGH",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 1.2,
          "impactScore": 1.4,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-15945",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-07-17T13:59:59.366659Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-07-16T18:16:42.693",
    "references": [
      {
        "source": "secalert@redhat.com",
        "url": "https://access.redhat.com/errata/RHSA-2026:68277"
      },
      {
        "source": "secalert@redhat.com",
        "url": "https://access.redhat.com/errata/RHSA-2026:68278"
      },
      {
        "source": "secalert@redhat.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://access.redhat.com/security/cve/CVE-2026-15945"
      },
      {
        "source": "secalert@redhat.com",
        "tags": [
          "Issue Tracking",
          "Vendor Advisory"
        ],
        "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2501302"
      }
    ],
    "sourceIdentifier": "secalert@redhat.com",
    "vulnStatus": "Modified",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-639"
          }
        ],
        "source": "secalert@redhat.com",
        "type": "Secondary"
      }
    ]
  }
}
—
CVSS vector
cvss_vector
not compared
Red HatCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
receipt
Source
Red Hat
Its words
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Read by
field:cvss3_scoring_vector
Said since
2026-10-06 13:01 UTC
Last answered
2026-10-06 13:02 UTC
Original
open at the source
2026-10-06 13:01 UTCCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
2026-09-29 09:44 UTC—
What the source handed over
{
  "CVE": "CVE-2026-15945",
  "CWE": "CWE-639",
  "advisories": [
    "RHSA-2026:68277",
    "RHSA-2026:68278"
  ],
  "affected_packages": [
    "rhbk-keycloak-rhel9/rhbk-keycloak-rhel9",
    "rhbk/keycloak-rhel9:26.6-20",
    "keycloak-services",
    "rhbk-openshift-rhel9/rhbk-openshift-rhel9",
    "rhbk/keycloak-rhel9-operator:26.6-20",
    "rhbk/keycloak-operator-bundle:26.6.7-3"
  ],
  "bugzilla": "2501302",
  "bugzilla_description": "keycloak-services: keycloak-services: Group hierarchy search discloses hidden parent groups under FGAP v2",
  "cvss3_score": "4.3",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-07-14T15:31:04Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-15945.json",
  "severity": "moderate"
}
—
CWE
cwe
NVDCWE-639
receipt
Source
NVD
Its words
CWE-639
Read by
field:cve.weaknesses[].description[].value
Said since
2026-10-06 12:29 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:29 UTCCWE-639
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "collectionURL": "https://catalog.redhat.com/software/containers/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.6::el9"
            ],
            "defaultStatus": "affected",
            "packageName": "rhbk/keycloak-operator-bundle",
            "product": "Red Hat build of Keycloak 26.6",
            "vendor": "Red Hat",
            "versions": [
              {
                "lessThan": "*",
                "status": "unaffected",
                "version": "26.6.7-3",
                "versionType": "rpm"
              }
            ]
          },
          {
            "collectionURL": "https://catalog.redhat.com/software/containers/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.6::el9"
            ],
            "defaultStatus": "affected",
            "packageName": "rhbk/keycloak-rhel9",
            "product": "Red Hat build of Keycloak 26.6",
            "vendor": "Red Hat",
            "versions": [
              {
                "lessThan": "*",
                "status": "unaffected",
                "version": "26.6-20",
                "versionType": "rpm"
              }
            ]
          },
          {
            "collectionURL": "https://catalog.redhat.com/software/containers/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.6::el9"
            ],
            "defaultStatus": "affected",
            "packageName": "rhbk/keycloak-rhel9-operator",
            "product": "Red Hat build of Keycloak 26.6",
            "vendor": "Red Hat",
            "versions": [
              {
                "lessThan": "*",
                "status": "unaffected",
                "version": "26.6-20",
                "versionType": "rpm"
              }
            ]
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.6::el9"
            ],
            "defaultStatus": "unaffected",
            "packageName": "keycloak-services",
            "product": "Red Hat build of Keycloak 26.6.7",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.6::el9"
            ],
            "defaultStatus": "unaffected",
            "packageName": "rhbk-keycloak-rhel9/rhbk-keycloak-rhel9",
            "product": "Red Hat build of Keycloak 26.6.7",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.6::el9"
            ],
            "defaultStatus": "unaffected",
            "packageName": "rhbk-openshift-rhel9/rhbk-openshift-rhel9",
            "product": "Red Hat build of Keycloak 26.6.7",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:jboss_data_grid:8"
            ],
            "defaultStatus": "affected",
            "packageName": "keycloak-services",
            "product": "Red Hat Data Grid 8",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://access.redhat.com/jbossnetwork/restricted/listSoftware.html",
            "cpes": [
              "cpe:/a:redhat:jbosseapxp"
            ],
            "defaultStatus": "affected",
            "packageName": "keycloak-services",
            "product": "Red Hat JBoss Enterprise Application Platform Expansion Pack",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:red_hat_single_sign_on:7"
            ],
            "defaultStatus": "affected",
            "packageName": "keycloak-services",
            "product": "Red Hat Single Sign-On 7",
            "vendor": "Red Hat"
          }
        ],
        "source": "secalert@redhat.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:redhat:build_of_keycloak:-:*:*:*:-:*:*:*",
                "matchCriteriaId": "E5C930CB-4EAD-497B-A44B-D880F2A1F85B",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:redhat:data_grid:8.0:*:*:*:*:*:*:*",
                "matchCriteriaId": "7095200A-4DAC-4433-99E8-86CA88E1E4D4",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:redhat:jboss_enterprise_application_platform_expansion_pack:-:*:*:*:*:*:*:*",
                "matchCriteriaId": "0A24CBFB-4900-47A5-88D2-A44C929603DC",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:redhat:single_sign-on:7.0:*:*:*:*:*:*:*",
                "matchCriteriaId": "9EFEC7CA-8DDA-48A6-A7B6-1F1D14792890",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A flaw was found in the group search functionality of the Keycloak server's administrative API. When Fine-Grained Admin Permissions (FGAP) v2 is enabled, a delegated administrator can bypass access restrictions to view parent groups they are not authorized to see. By searching for a child group they have permission to view, the system incorrectly returns the full details of the parent group in the response, leading to the disclosure of sensitive group attributes and configuration."
      }
    ],
    "id": "CVE-2026-15945",
    "lastModified": "2026-09-16T19:17:06.900",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 4.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 1.4,
          "source": "secalert@redhat.com",
          "type": "Secondary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 2.7,
            "baseSeverity": "LOW",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "HIGH",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 1.2,
          "impactScore": 1.4,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-15945",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-07-17T13:59:59.366659Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-07-16T18:16:42.693",
    "references": [
      {
        "source": "secalert@redhat.com",
        "url": "https://access.redhat.com/errata/RHSA-2026:68277"
      },
      {
        "source": "secalert@redhat.com",
        "url": "https://access.redhat.com/errata/RHSA-2026:68278"
      },
      {
        "source": "secalert@redhat.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://access.redhat.com/security/cve/CVE-2026-15945"
      },
      {
        "source": "secalert@redhat.com",
        "tags": [
          "Issue Tracking",
          "Vendor Advisory"
        ],
        "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2501302"
      }
    ],
    "sourceIdentifier": "secalert@redhat.com",
    "vulnStatus": "Modified",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-639"
          }
        ],
        "source": "secalert@redhat.com",
        "type": "Secondary"
      }
    ]
  }
}
—
CWE
cwe
Red HatCWE-639
receipt
Source
Red Hat
Its words
CWE-639
Read by
field:CWE
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-06 13:02 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2026-15945",
  "CWE": "CWE-639",
  "advisories": [
    "RHSA-2026:68277",
    "RHSA-2026:68278"
  ],
  "affected_packages": [
    "rhbk-keycloak-rhel9/rhbk-keycloak-rhel9",
    "rhbk/keycloak-rhel9:26.6-20",
    "keycloak-services",
    "rhbk-openshift-rhel9/rhbk-openshift-rhel9",
    "rhbk/keycloak-rhel9-operator:26.6-20",
    "rhbk/keycloak-operator-bundle:26.6.7-3"
  ],
  "bugzilla": "2501302",
  "bugzilla_description": "keycloak-services: keycloak-services: Group hierarchy search discloses hidden parent groups under FGAP v2",
  "cvss3_score": "4.3",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-07-14T15:31:04Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-15945.json",
  "severity": "moderate"
}
—
Exploitation
exploitation
NVDnone
No evidence of exploitation, and no public proof of concept.
receipt
Source
NVD
Its words
none
Read by
field:cve.metrics.ssvcV203[].ssvcData.options[].exploitation
Said since
2026-10-06 12:29 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:29 UTCnone
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "collectionURL": "https://catalog.redhat.com/software/containers/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.6::el9"
            ],
            "defaultStatus": "affected",
            "packageName": "rhbk/keycloak-operator-bundle",
            "product": "Red Hat build of Keycloak 26.6",
            "vendor": "Red Hat",
            "versions": [
              {
                "lessThan": "*",
                "status": "unaffected",
                "version": "26.6.7-3",
                "versionType": "rpm"
              }
            ]
          },
          {
            "collectionURL": "https://catalog.redhat.com/software/containers/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.6::el9"
            ],
            "defaultStatus": "affected",
            "packageName": "rhbk/keycloak-rhel9",
            "product": "Red Hat build of Keycloak 26.6",
            "vendor": "Red Hat",
            "versions": [
              {
                "lessThan": "*",
                "status": "unaffected",
                "version": "26.6-20",
                "versionType": "rpm"
              }
            ]
          },
          {
            "collectionURL": "https://catalog.redhat.com/software/containers/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.6::el9"
            ],
            "defaultStatus": "affected",
            "packageName": "rhbk/keycloak-rhel9-operator",
            "product": "Red Hat build of Keycloak 26.6",
            "vendor": "Red Hat",
            "versions": [
              {
                "lessThan": "*",
                "status": "unaffected",
                "version": "26.6-20",
                "versionType": "rpm"
              }
            ]
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.6::el9"
            ],
            "defaultStatus": "unaffected",
            "packageName": "keycloak-services",
            "product": "Red Hat build of Keycloak 26.6.7",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.6::el9"
            ],
            "defaultStatus": "unaffected",
            "packageName": "rhbk-keycloak-rhel9/rhbk-keycloak-rhel9",
            "product": "Red Hat build of Keycloak 26.6.7",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.6::el9"
            ],
            "defaultStatus": "unaffected",
            "packageName": "rhbk-openshift-rhel9/rhbk-openshift-rhel9",
            "product": "Red Hat build of Keycloak 26.6.7",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:jboss_data_grid:8"
            ],
            "defaultStatus": "affected",
            "packageName": "keycloak-services",
            "product": "Red Hat Data Grid 8",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://access.redhat.com/jbossnetwork/restricted/listSoftware.html",
            "cpes": [
              "cpe:/a:redhat:jbosseapxp"
            ],
            "defaultStatus": "affected",
            "packageName": "keycloak-services",
            "product": "Red Hat JBoss Enterprise Application Platform Expansion Pack",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:red_hat_single_sign_on:7"
            ],
            "defaultStatus": "affected",
            "packageName": "keycloak-services",
            "product": "Red Hat Single Sign-On 7",
            "vendor": "Red Hat"
          }
        ],
        "source": "secalert@redhat.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:redhat:build_of_keycloak:-:*:*:*:-:*:*:*",
                "matchCriteriaId": "E5C930CB-4EAD-497B-A44B-D880F2A1F85B",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:redhat:data_grid:8.0:*:*:*:*:*:*:*",
                "matchCriteriaId": "7095200A-4DAC-4433-99E8-86CA88E1E4D4",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:redhat:jboss_enterprise_application_platform_expansion_pack:-:*:*:*:*:*:*:*",
                "matchCriteriaId": "0A24CBFB-4900-47A5-88D2-A44C929603DC",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:redhat:single_sign-on:7.0:*:*:*:*:*:*:*",
                "matchCriteriaId": "9EFEC7CA-8DDA-48A6-A7B6-1F1D14792890",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A flaw was found in the group search functionality of the Keycloak server's administrative API. When Fine-Grained Admin Permissions (FGAP) v2 is enabled, a delegated administrator can bypass access restrictions to view parent groups they are not authorized to see. By searching for a child group they have permission to view, the system incorrectly returns the full details of the parent group in the response, leading to the disclosure of sensitive group attributes and configuration."
      }
    ],
    "id": "CVE-2026-15945",
    "lastModified": "2026-09-16T19:17:06.900",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 4.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 1.4,
          "source": "secalert@redhat.com",
          "type": "Secondary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 2.7,
            "baseSeverity": "LOW",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "HIGH",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 1.2,
          "impactScore": 1.4,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-15945",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-07-17T13:59:59.366659Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-07-16T18:16:42.693",
    "references": [
      {
        "source": "secalert@redhat.com",
        "url": "https://access.redhat.com/errata/RHSA-2026:68277"
      },
      {
        "source": "secalert@redhat.com",
        "url": "https://access.redhat.com/errata/RHSA-2026:68278"
      },
      {
        "source": "secalert@redhat.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://access.redhat.com/security/cve/CVE-2026-15945"
      },
      {
        "source": "secalert@redhat.com",
        "tags": [
          "Issue Tracking",
          "Vendor Advisory"
        ],
        "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2501302"
      }
    ],
    "sourceIdentifier": "secalert@redhat.com",
    "vulnStatus": "Modified",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-639"
          }
        ],
        "source": "secalert@redhat.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Packages
packages
Red Hatrhbk-keycloak-rhel9/rhbk-keycloak-rhel9, rhbk/keycloak-rhel9:26.6-20, keycloak-services, rhbk-openshift-rhel9/rhbk-openshift-rhel9, rhbk/keycloak-rhel9-operator:26.6-20, rhbk/keycloak-operator-bundle:26.6.7-3
receipt
Source
Red Hat
Its words
rhbk-keycloak-rhel9/rhbk-keycloak-rhel9, rhbk/keycloak-rhel9:26.6-20, keycloak-services, rhbk-openshift-rhel9/rhbk-openshift-rhel9, rhbk/keycloak-rhel9-operator:26.6-20, rhbk/keycloak-operator-bundle:26.6.7-3
Read by
field:affected_packages[]
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-06 13:02 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2026-15945",
  "CWE": "CWE-639",
  "advisories": [
    "RHSA-2026:68277",
    "RHSA-2026:68278"
  ],
  "affected_packages": [
    "rhbk-keycloak-rhel9/rhbk-keycloak-rhel9",
    "rhbk/keycloak-rhel9:26.6-20",
    "keycloak-services",
    "rhbk-openshift-rhel9/rhbk-openshift-rhel9",
    "rhbk/keycloak-rhel9-operator:26.6-20",
    "rhbk/keycloak-operator-bundle:26.6.7-3"
  ],
  "bugzilla": "2501302",
  "bugzilla_description": "keycloak-services: keycloak-services: Group hierarchy search discloses hidden parent groups under FGAP v2",
  "cvss3_score": "4.3",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-07-14T15:31:04Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-15945.json",
  "severity": "moderate"
}
—
Product
product
NVDRed Hat build of Keycloak 26.6
receipt
Source
NVD
Its words
Red Hat build of Keycloak 26.6
Read by
field:cve.affected[].affectedData[].product
Said since
2026-09-29 17:49 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-09-29 17:49 UTCRed Hat build of Keycloak 26.6
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "collectionURL": "https://catalog.redhat.com/software/containers/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.6::el9"
            ],
            "defaultStatus": "affected",
            "packageName": "rhbk/keycloak-operator-bundle",
            "product": "Red Hat build of Keycloak 26.6",
            "vendor": "Red Hat",
            "versions": [
              {
                "lessThan": "*",
                "status": "unaffected",
                "version": "26.6.7-3",
                "versionType": "rpm"
              }
            ]
          },
          {
            "collectionURL": "https://catalog.redhat.com/software/containers/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.6::el9"
            ],
            "defaultStatus": "affected",
            "packageName": "rhbk/keycloak-rhel9",
            "product": "Red Hat build of Keycloak 26.6",
            "vendor": "Red Hat",
            "versions": [
              {
                "lessThan": "*",
                "status": "unaffected",
                "version": "26.6-20",
                "versionType": "rpm"
              }
            ]
          },
          {
            "collectionURL": "https://catalog.redhat.com/software/containers/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.6::el9"
            ],
            "defaultStatus": "affected",
            "packageName": "rhbk/keycloak-rhel9-operator",
            "product": "Red Hat build of Keycloak 26.6",
            "vendor": "Red Hat",
            "versions": [
              {
                "lessThan": "*",
                "status": "unaffected",
                "version": "26.6-20",
                "versionType": "rpm"
              }
            ]
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.6::el9"
            ],
            "defaultStatus": "unaffected",
            "packageName": "keycloak-services",
            "product": "Red Hat build of Keycloak 26.6.7",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.6::el9"
            ],
            "defaultStatus": "unaffected",
            "packageName": "rhbk-keycloak-rhel9/rhbk-keycloak-rhel9",
            "product": "Red Hat build of Keycloak 26.6.7",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.6::el9"
            ],
            "defaultStatus": "unaffected",
            "packageName": "rhbk-openshift-rhel9/rhbk-openshift-rhel9",
            "product": "Red Hat build of Keycloak 26.6.7",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:jboss_data_grid:8"
            ],
            "defaultStatus": "affected",
            "packageName": "keycloak-services",
            "product": "Red Hat Data Grid 8",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://access.redhat.com/jbossnetwork/restricted/listSoftware.html",
            "cpes": [
              "cpe:/a:redhat:jbosseapxp"
            ],
            "defaultStatus": "affected",
            "packageName": "keycloak-services",
            "product": "Red Hat JBoss Enterprise Application Platform Expansion Pack",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:red_hat_single_sign_on:7"
            ],
            "defaultStatus": "affected",
            "packageName": "keycloak-services",
            "product": "Red Hat Single Sign-On 7",
            "vendor": "Red Hat"
          }
        ],
        "source": "secalert@redhat.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:redhat:build_of_keycloak:-:*:*:*:-:*:*:*",
                "matchCriteriaId": "E5C930CB-4EAD-497B-A44B-D880F2A1F85B",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:redhat:data_grid:8.0:*:*:*:*:*:*:*",
                "matchCriteriaId": "7095200A-4DAC-4433-99E8-86CA88E1E4D4",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:redhat:jboss_enterprise_application_platform_expansion_pack:-:*:*:*:*:*:*:*",
                "matchCriteriaId": "0A24CBFB-4900-47A5-88D2-A44C929603DC",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:redhat:single_sign-on:7.0:*:*:*:*:*:*:*",
                "matchCriteriaId": "9EFEC7CA-8DDA-48A6-A7B6-1F1D14792890",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A flaw was found in the group search functionality of the Keycloak server's administrative API. When Fine-Grained Admin Permissions (FGAP) v2 is enabled, a delegated administrator can bypass access restrictions to view parent groups they are not authorized to see. By searching for a child group they have permission to view, the system incorrectly returns the full details of the parent group in the response, leading to the disclosure of sensitive group attributes and configuration."
      }
    ],
    "id": "CVE-2026-15945",
    "lastModified": "2026-09-16T19:17:06.900",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 4.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 1.4,
          "source": "secalert@redhat.com",
          "type": "Secondary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 2.7,
            "baseSeverity": "LOW",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "HIGH",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 1.2,
          "impactScore": 1.4,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-15945",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-07-17T13:59:59.366659Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-07-16T18:16:42.693",
    "references": [
      {
        "source": "secalert@redhat.com",
        "url": "https://access.redhat.com/errata/RHSA-2026:68277"
      },
      {
        "source": "secalert@redhat.com",
        "url": "https://access.redhat.com/errata/RHSA-2026:68278"
      },
      {
        "source": "secalert@redhat.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://access.redhat.com/security/cve/CVE-2026-15945"
      },
      {
        "source": "secalert@redhat.com",
        "tags": [
          "Issue Tracking",
          "Vendor Advisory"
        ],
        "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2501302"
      }
    ],
    "sourceIdentifier": "secalert@redhat.com",
    "vulnStatus": "Modified",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-639"
          }
        ],
        "source": "secalert@redhat.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Severity
severity
conflict
NVDLOW
From 0.1 to 3.9.
receipt
Source
NVD
Its words
LOW
Read by
field:cve.metrics.cvssMetricV31[type=Primary].cvssData.baseSeverity || field:cve.metrics.cvssMetricV31[].cvssData.baseSeverity
Said since
2026-10-06 12:29 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:29 UTCLOW
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "collectionURL": "https://catalog.redhat.com/software/containers/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.6::el9"
            ],
            "defaultStatus": "affected",
            "packageName": "rhbk/keycloak-operator-bundle",
            "product": "Red Hat build of Keycloak 26.6",
            "vendor": "Red Hat",
            "versions": [
              {
                "lessThan": "*",
                "status": "unaffected",
                "version": "26.6.7-3",
                "versionType": "rpm"
              }
            ]
          },
          {
            "collectionURL": "https://catalog.redhat.com/software/containers/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.6::el9"
            ],
            "defaultStatus": "affected",
            "packageName": "rhbk/keycloak-rhel9",
            "product": "Red Hat build of Keycloak 26.6",
            "vendor": "Red Hat",
            "versions": [
              {
                "lessThan": "*",
                "status": "unaffected",
                "version": "26.6-20",
                "versionType": "rpm"
              }
            ]
          },
          {
            "collectionURL": "https://catalog.redhat.com/software/containers/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.6::el9"
            ],
            "defaultStatus": "affected",
            "packageName": "rhbk/keycloak-rhel9-operator",
            "product": "Red Hat build of Keycloak 26.6",
            "vendor": "Red Hat",
            "versions": [
              {
                "lessThan": "*",
                "status": "unaffected",
                "version": "26.6-20",
                "versionType": "rpm"
              }
            ]
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.6::el9"
            ],
            "defaultStatus": "unaffected",
            "packageName": "keycloak-services",
            "product": "Red Hat build of Keycloak 26.6.7",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.6::el9"
            ],
            "defaultStatus": "unaffected",
            "packageName": "rhbk-keycloak-rhel9/rhbk-keycloak-rhel9",
            "product": "Red Hat build of Keycloak 26.6.7",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.6::el9"
            ],
            "defaultStatus": "unaffected",
            "packageName": "rhbk-openshift-rhel9/rhbk-openshift-rhel9",
            "product": "Red Hat build of Keycloak 26.6.7",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:jboss_data_grid:8"
            ],
            "defaultStatus": "affected",
            "packageName": "keycloak-services",
            "product": "Red Hat Data Grid 8",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://access.redhat.com/jbossnetwork/restricted/listSoftware.html",
            "cpes": [
              "cpe:/a:redhat:jbosseapxp"
            ],
            "defaultStatus": "affected",
            "packageName": "keycloak-services",
            "product": "Red Hat JBoss Enterprise Application Platform Expansion Pack",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:red_hat_single_sign_on:7"
            ],
            "defaultStatus": "affected",
            "packageName": "keycloak-services",
            "product": "Red Hat Single Sign-On 7",
            "vendor": "Red Hat"
          }
        ],
        "source": "secalert@redhat.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:redhat:build_of_keycloak:-:*:*:*:-:*:*:*",
                "matchCriteriaId": "E5C930CB-4EAD-497B-A44B-D880F2A1F85B",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:redhat:data_grid:8.0:*:*:*:*:*:*:*",
                "matchCriteriaId": "7095200A-4DAC-4433-99E8-86CA88E1E4D4",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:redhat:jboss_enterprise_application_platform_expansion_pack:-:*:*:*:*:*:*:*",
                "matchCriteriaId": "0A24CBFB-4900-47A5-88D2-A44C929603DC",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:redhat:single_sign-on:7.0:*:*:*:*:*:*:*",
                "matchCriteriaId": "9EFEC7CA-8DDA-48A6-A7B6-1F1D14792890",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A flaw was found in the group search functionality of the Keycloak server's administrative API. When Fine-Grained Admin Permissions (FGAP) v2 is enabled, a delegated administrator can bypass access restrictions to view parent groups they are not authorized to see. By searching for a child group they have permission to view, the system incorrectly returns the full details of the parent group in the response, leading to the disclosure of sensitive group attributes and configuration."
      }
    ],
    "id": "CVE-2026-15945",
    "lastModified": "2026-09-16T19:17:06.900",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 4.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 1.4,
          "source": "secalert@redhat.com",
          "type": "Secondary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 2.7,
            "baseSeverity": "LOW",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "HIGH",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 1.2,
          "impactScore": 1.4,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-15945",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-07-17T13:59:59.366659Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-07-16T18:16:42.693",
    "references": [
      {
        "source": "secalert@redhat.com",
        "url": "https://access.redhat.com/errata/RHSA-2026:68277"
      },
      {
        "source": "secalert@redhat.com",
        "url": "https://access.redhat.com/errata/RHSA-2026:68278"
      },
      {
        "source": "secalert@redhat.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://access.redhat.com/security/cve/CVE-2026-15945"
      },
      {
        "source": "secalert@redhat.com",
        "tags": [
          "Issue Tracking",
          "Vendor Advisory"
        ],
        "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2501302"
      }
    ],
    "sourceIdentifier": "secalert@redhat.com",
    "vulnStatus": "Modified",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-639"
          }
        ],
        "source": "secalert@redhat.com",
        "type": "Secondary"
      }
    ]
  }
}
low
Severity
severity
conflict
Red Hatmoderate
A flaw that is harder to exploit, or whose impact is limited.
receipt
Source
Red Hat
Its words
moderate
Read by
field:severity
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-06 13:02 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2026-15945",
  "CWE": "CWE-639",
  "advisories": [
    "RHSA-2026:68277",
    "RHSA-2026:68278"
  ],
  "affected_packages": [
    "rhbk-keycloak-rhel9/rhbk-keycloak-rhel9",
    "rhbk/keycloak-rhel9:26.6-20",
    "keycloak-services",
    "rhbk-openshift-rhel9/rhbk-openshift-rhel9",
    "rhbk/keycloak-rhel9-operator:26.6-20",
    "rhbk/keycloak-operator-bundle:26.6.7-3"
  ],
  "bugzilla": "2501302",
  "bugzilla_description": "keycloak-services: keycloak-services: Group hierarchy search discloses hidden parent groups under FGAP v2",
  "cvss3_score": "4.3",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-07-14T15:31:04Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-15945.json",
  "severity": "moderate"
}
medium
Status
status
NVDModified
receipt
Source
NVD
Its words
Modified
Read by
field:cve.vulnStatus
Said since
2026-09-29 09:45 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "collectionURL": "https://catalog.redhat.com/software/containers/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.6::el9"
            ],
            "defaultStatus": "affected",
            "packageName": "rhbk/keycloak-operator-bundle",
            "product": "Red Hat build of Keycloak 26.6",
            "vendor": "Red Hat",
            "versions": [
              {
                "lessThan": "*",
                "status": "unaffected",
                "version": "26.6.7-3",
                "versionType": "rpm"
              }
            ]
          },
          {
            "collectionURL": "https://catalog.redhat.com/software/containers/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.6::el9"
            ],
            "defaultStatus": "affected",
            "packageName": "rhbk/keycloak-rhel9",
            "product": "Red Hat build of Keycloak 26.6",
            "vendor": "Red Hat",
            "versions": [
              {
                "lessThan": "*",
                "status": "unaffected",
                "version": "26.6-20",
                "versionType": "rpm"
              }
            ]
          },
          {
            "collectionURL": "https://catalog.redhat.com/software/containers/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.6::el9"
            ],
            "defaultStatus": "affected",
            "packageName": "rhbk/keycloak-rhel9-operator",
            "product": "Red Hat build of Keycloak 26.6",
            "vendor": "Red Hat",
            "versions": [
              {
                "lessThan": "*",
                "status": "unaffected",
                "version": "26.6-20",
                "versionType": "rpm"
              }
            ]
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.6::el9"
            ],
            "defaultStatus": "unaffected",
            "packageName": "keycloak-services",
            "product": "Red Hat build of Keycloak 26.6.7",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.6::el9"
            ],
            "defaultStatus": "unaffected",
            "packageName": "rhbk-keycloak-rhel9/rhbk-keycloak-rhel9",
            "product": "Red Hat build of Keycloak 26.6.7",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.6::el9"
            ],
            "defaultStatus": "unaffected",
            "packageName": "rhbk-openshift-rhel9/rhbk-openshift-rhel9",
            "product": "Red Hat build of Keycloak 26.6.7",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:jboss_data_grid:8"
            ],
            "defaultStatus": "affected",
            "packageName": "keycloak-services",
            "product": "Red Hat Data Grid 8",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://access.redhat.com/jbossnetwork/restricted/listSoftware.html",
            "cpes": [
              "cpe:/a:redhat:jbosseapxp"
            ],
            "defaultStatus": "affected",
            "packageName": "keycloak-services",
            "product": "Red Hat JBoss Enterprise Application Platform Expansion Pack",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:red_hat_single_sign_on:7"
            ],
            "defaultStatus": "affected",
            "packageName": "keycloak-services",
            "product": "Red Hat Single Sign-On 7",
            "vendor": "Red Hat"
          }
        ],
        "source": "secalert@redhat.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:redhat:build_of_keycloak:-:*:*:*:-:*:*:*",
                "matchCriteriaId": "E5C930CB-4EAD-497B-A44B-D880F2A1F85B",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:redhat:data_grid:8.0:*:*:*:*:*:*:*",
                "matchCriteriaId": "7095200A-4DAC-4433-99E8-86CA88E1E4D4",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:redhat:jboss_enterprise_application_platform_expansion_pack:-:*:*:*:*:*:*:*",
                "matchCriteriaId": "0A24CBFB-4900-47A5-88D2-A44C929603DC",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:redhat:single_sign-on:7.0:*:*:*:*:*:*:*",
                "matchCriteriaId": "9EFEC7CA-8DDA-48A6-A7B6-1F1D14792890",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A flaw was found in the group search functionality of the Keycloak server's administrative API. When Fine-Grained Admin Permissions (FGAP) v2 is enabled, a delegated administrator can bypass access restrictions to view parent groups they are not authorized to see. By searching for a child group they have permission to view, the system incorrectly returns the full details of the parent group in the response, leading to the disclosure of sensitive group attributes and configuration."
      }
    ],
    "id": "CVE-2026-15945",
    "lastModified": "2026-09-16T19:17:06.900",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 4.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 1.4,
          "source": "secalert@redhat.com",
          "type": "Secondary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 2.7,
            "baseSeverity": "LOW",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "HIGH",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 1.2,
          "impactScore": 1.4,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-15945",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-07-17T13:59:59.366659Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-07-16T18:16:42.693",
    "references": [
      {
        "source": "secalert@redhat.com",
        "url": "https://access.redhat.com/errata/RHSA-2026:68277"
      },
      {
        "source": "secalert@redhat.com",
        "url": "https://access.redhat.com/errata/RHSA-2026:68278"
      },
      {
        "source": "secalert@redhat.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://access.redhat.com/security/cve/CVE-2026-15945"
      },
      {
        "source": "secalert@redhat.com",
        "tags": [
          "Issue Tracking",
          "Vendor Advisory"
        ],
        "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2501302"
      }
    ],
    "sourceIdentifier": "secalert@redhat.com",
    "vulnStatus": "Modified",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-639"
          }
        ],
        "source": "secalert@redhat.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Technical impact
technical_impact
NVDpartial
The attacker gains limited control, or limited information.
receipt
Source
NVD
Its words
partial
Read by
field:cve.metrics.ssvcV203[].ssvcData.options[].technicalImpact
Said since
2026-10-06 12:29 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:29 UTCpartial
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "collectionURL": "https://catalog.redhat.com/software/containers/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.6::el9"
            ],
            "defaultStatus": "affected",
            "packageName": "rhbk/keycloak-operator-bundle",
            "product": "Red Hat build of Keycloak 26.6",
            "vendor": "Red Hat",
            "versions": [
              {
                "lessThan": "*",
                "status": "unaffected",
                "version": "26.6.7-3",
                "versionType": "rpm"
              }
            ]
          },
          {
            "collectionURL": "https://catalog.redhat.com/software/containers/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.6::el9"
            ],
            "defaultStatus": "affected",
            "packageName": "rhbk/keycloak-rhel9",
            "product": "Red Hat build of Keycloak 26.6",
            "vendor": "Red Hat",
            "versions": [
              {
                "lessThan": "*",
                "status": "unaffected",
                "version": "26.6-20",
                "versionType": "rpm"
              }
            ]
          },
          {
            "collectionURL": "https://catalog.redhat.com/software/containers/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.6::el9"
            ],
            "defaultStatus": "affected",
            "packageName": "rhbk/keycloak-rhel9-operator",
            "product": "Red Hat build of Keycloak 26.6",
            "vendor": "Red Hat",
            "versions": [
              {
                "lessThan": "*",
                "status": "unaffected",
                "version": "26.6-20",
                "versionType": "rpm"
              }
            ]
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.6::el9"
            ],
            "defaultStatus": "unaffected",
            "packageName": "keycloak-services",
            "product": "Red Hat build of Keycloak 26.6.7",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.6::el9"
            ],
            "defaultStatus": "unaffected",
            "packageName": "rhbk-keycloak-rhel9/rhbk-keycloak-rhel9",
            "product": "Red Hat build of Keycloak 26.6.7",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.6::el9"
            ],
            "defaultStatus": "unaffected",
            "packageName": "rhbk-openshift-rhel9/rhbk-openshift-rhel9",
            "product": "Red Hat build of Keycloak 26.6.7",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:jboss_data_grid:8"
            ],
            "defaultStatus": "affected",
            "packageName": "keycloak-services",
            "product": "Red Hat Data Grid 8",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://access.redhat.com/jbossnetwork/restricted/listSoftware.html",
            "cpes": [
              "cpe:/a:redhat:jbosseapxp"
            ],
            "defaultStatus": "affected",
            "packageName": "keycloak-services",
            "product": "Red Hat JBoss Enterprise Application Platform Expansion Pack",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:red_hat_single_sign_on:7"
            ],
            "defaultStatus": "affected",
            "packageName": "keycloak-services",
            "product": "Red Hat Single Sign-On 7",
            "vendor": "Red Hat"
          }
        ],
        "source": "secalert@redhat.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:redhat:build_of_keycloak:-:*:*:*:-:*:*:*",
                "matchCriteriaId": "E5C930CB-4EAD-497B-A44B-D880F2A1F85B",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:redhat:data_grid:8.0:*:*:*:*:*:*:*",
                "matchCriteriaId": "7095200A-4DAC-4433-99E8-86CA88E1E4D4",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:redhat:jboss_enterprise_application_platform_expansion_pack:-:*:*:*:*:*:*:*",
                "matchCriteriaId": "0A24CBFB-4900-47A5-88D2-A44C929603DC",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:redhat:single_sign-on:7.0:*:*:*:*:*:*:*",
                "matchCriteriaId": "9EFEC7CA-8DDA-48A6-A7B6-1F1D14792890",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A flaw was found in the group search functionality of the Keycloak server's administrative API. When Fine-Grained Admin Permissions (FGAP) v2 is enabled, a delegated administrator can bypass access restrictions to view parent groups they are not authorized to see. By searching for a child group they have permission to view, the system incorrectly returns the full details of the parent group in the response, leading to the disclosure of sensitive group attributes and configuration."
      }
    ],
    "id": "CVE-2026-15945",
    "lastModified": "2026-09-16T19:17:06.900",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 4.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 1.4,
          "source": "secalert@redhat.com",
          "type": "Secondary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 2.7,
            "baseSeverity": "LOW",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "HIGH",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 1.2,
          "impactScore": 1.4,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-15945",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-07-17T13:59:59.366659Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-07-16T18:16:42.693",
    "references": [
      {
        "source": "secalert@redhat.com",
        "url": "https://access.redhat.com/errata/RHSA-2026:68277"
      },
      {
        "source": "secalert@redhat.com",
        "url": "https://access.redhat.com/errata/RHSA-2026:68278"
      },
      {
        "source": "secalert@redhat.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://access.redhat.com/security/cve/CVE-2026-15945"
      },
      {
        "source": "secalert@redhat.com",
        "tags": [
          "Issue Tracking",
          "Vendor Advisory"
        ],
        "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2501302"
      }
    ],
    "sourceIdentifier": "secalert@redhat.com",
    "vulnStatus": "Modified",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-639"
          }
        ],
        "source": "secalert@redhat.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Vendor
vendor
NVDRed Hat
receipt
Source
NVD
Its words
Red Hat
Read by
field:cve.affected[].affectedData[].vendor
Said since
2026-09-29 17:49 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-09-29 17:49 UTCRed Hat
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "collectionURL": "https://catalog.redhat.com/software/containers/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.6::el9"
            ],
            "defaultStatus": "affected",
            "packageName": "rhbk/keycloak-operator-bundle",
            "product": "Red Hat build of Keycloak 26.6",
            "vendor": "Red Hat",
            "versions": [
              {
                "lessThan": "*",
                "status": "unaffected",
                "version": "26.6.7-3",
                "versionType": "rpm"
              }
            ]
          },
          {
            "collectionURL": "https://catalog.redhat.com/software/containers/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.6::el9"
            ],
            "defaultStatus": "affected",
            "packageName": "rhbk/keycloak-rhel9",
            "product": "Red Hat build of Keycloak 26.6",
            "vendor": "Red Hat",
            "versions": [
              {
                "lessThan": "*",
                "status": "unaffected",
                "version": "26.6-20",
                "versionType": "rpm"
              }
            ]
          },
          {
            "collectionURL": "https://catalog.redhat.com/software/containers/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.6::el9"
            ],
            "defaultStatus": "affected",
            "packageName": "rhbk/keycloak-rhel9-operator",
            "product": "Red Hat build of Keycloak 26.6",
            "vendor": "Red Hat",
            "versions": [
              {
                "lessThan": "*",
                "status": "unaffected",
                "version": "26.6-20",
                "versionType": "rpm"
              }
            ]
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.6::el9"
            ],
            "defaultStatus": "unaffected",
            "packageName": "keycloak-services",
            "product": "Red Hat build of Keycloak 26.6.7",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.6::el9"
            ],
            "defaultStatus": "unaffected",
            "packageName": "rhbk-keycloak-rhel9/rhbk-keycloak-rhel9",
            "product": "Red Hat build of Keycloak 26.6.7",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.6::el9"
            ],
            "defaultStatus": "unaffected",
            "packageName": "rhbk-openshift-rhel9/rhbk-openshift-rhel9",
            "product": "Red Hat build of Keycloak 26.6.7",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:jboss_data_grid:8"
            ],
            "defaultStatus": "affected",
            "packageName": "keycloak-services",
            "product": "Red Hat Data Grid 8",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://access.redhat.com/jbossnetwork/restricted/listSoftware.html",
            "cpes": [
              "cpe:/a:redhat:jbosseapxp"
            ],
            "defaultStatus": "affected",
            "packageName": "keycloak-services",
            "product": "Red Hat JBoss Enterprise Application Platform Expansion Pack",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:red_hat_single_sign_on:7"
            ],
            "defaultStatus": "affected",
            "packageName": "keycloak-services",
            "product": "Red Hat Single Sign-On 7",
            "vendor": "Red Hat"
          }
        ],
        "source": "secalert@redhat.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:redhat:build_of_keycloak:-:*:*:*:-:*:*:*",
                "matchCriteriaId": "E5C930CB-4EAD-497B-A44B-D880F2A1F85B",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:redhat:data_grid:8.0:*:*:*:*:*:*:*",
                "matchCriteriaId": "7095200A-4DAC-4433-99E8-86CA88E1E4D4",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:redhat:jboss_enterprise_application_platform_expansion_pack:-:*:*:*:*:*:*:*",
                "matchCriteriaId": "0A24CBFB-4900-47A5-88D2-A44C929603DC",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:redhat:single_sign-on:7.0:*:*:*:*:*:*:*",
                "matchCriteriaId": "9EFEC7CA-8DDA-48A6-A7B6-1F1D14792890",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A flaw was found in the group search functionality of the Keycloak server's administrative API. When Fine-Grained Admin Permissions (FGAP) v2 is enabled, a delegated administrator can bypass access restrictions to view parent groups they are not authorized to see. By searching for a child group they have permission to view, the system incorrectly returns the full details of the parent group in the response, leading to the disclosure of sensitive group attributes and configuration."
      }
    ],
    "id": "CVE-2026-15945",
    "lastModified": "2026-09-16T19:17:06.900",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 4.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 1.4,
          "source": "secalert@redhat.com",
          "type": "Secondary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 2.7,
            "baseSeverity": "LOW",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "HIGH",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 1.2,
          "impactScore": 1.4,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-15945",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-07-17T13:59:59.366659Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-07-16T18:16:42.693",
    "references": [
      {
        "source": "secalert@redhat.com",
        "url": "https://access.redhat.com/errata/RHSA-2026:68277"
      },
      {
        "source": "secalert@redhat.com",
        "url": "https://access.redhat.com/errata/RHSA-2026:68278"
      },
      {
        "source": "secalert@redhat.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://access.redhat.com/security/cve/CVE-2026-15945"
      },
      {
        "source": "secalert@redhat.com",
        "tags": [
          "Issue Tracking",
          "Vendor Advisory"
        ],
        "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2501302"
      }
    ],
    "sourceIdentifier": "secalert@redhat.com",
    "vulnStatus": "Modified",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-639"
          }
        ],
        "source": "secalert@redhat.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Every claim, by kind

vulnerability

keycloak-services: keycloak-services: Group hierarchy search discloses hidden parent groups under FGAP v2
zetlyn/cve-redhat · 2026-07-14
cvss 4.3 cvss_vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N cwe CWE-639 packages rhbk-keycloak-rhel9/rhbk-keycloak-rhel9, rhbk/keycloak-rhel9:26.6-20, keycloak-services, rhbk-openshift-rhel9/rhbk-openshift-rhel9, rhbk/keycloak-rhel9-operator:26.6-20, rhbk/keycloak-operator-bundle:26.6.7-3 severity moderate source
A flaw was found in the group search functionality of the Keycloak server's administrative API. When Fine-Grained Admin Permissions (FGAP) v2 is enabled, a delegated administrator can bypass access restrictions to view parent groups they are not authorized to see. By searching for a child group they have permission to view, the system incorrectly returns the full details of the parent group in the response, leading to the disclosure of sensitive group attributes and configuration.
zetlyn/cve-nvd · 2026-07-16
automatable no cvss 2.7 cvss_vector CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N cwe CWE-639 exploitation none product Red Hat build of Keycloak 26.6 severity LOW status Modified technical_impact partial vendor Red Hat source