Impact
A flaw in Keycloak’s Fine‑Grained Admin Permissions (FGAP) v2 implementation causes the system to return details of child groups when a delegated administrator requests a parent group. The returned information includes child group names, paths, and custom attributes, even when the administrator does not have permission to view those child groups. This violates row‑level access controls (CWE‑1220) and exposes sensitive group hierarchy data that is not meant to be publicly available.
Affected Systems
Deployments of the Red Hat Build of Keycloak with FGAP v2 enabled are affected. No specific version numbers are listed, so the vulnerability applies to all instances where the feature is active.
Risk and Exploitability
The likely attack vector is an authenticated administrative user issuing an HTTP request to the parent group endpoint when FGAP v2 is enabled. The CVSS score of 4.3 indicates low severity; the EPSS score < 1% indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Exposing group structure and attributes but does not grant additional privileges beyond the information disclosed.
OpenCVE Enrichment