Impact
Keycloak’s Fine‑Grained Admin Permissions (FGAP) v2 contains a flaw where child groups are not filtered according to the caller’s permissions when requested via a parent group endpoint. An authenticated delegated administrator can retrieve child group names, paths, and custom attributes that they are not authorized to see. This bypass violates row‑level access controls (CWE‑1220) and exposes sensitive group hierarchy information that should be confidential.
Affected Systems
Deployments of the Red Hat Build of Keycloak with Fine‑Grained Admin Permissions v2 enabled are affected. Version details are not specified, so the issue applies to all instances where FGAP v2 is active.
Risk and Exploitability
The likely attack vector is an authenticated administrative user issuing an HTTP request to the parent group endpoint when FGAP v2 is enabled. The CVSS score of 4.3 reflects low severity, and the EPSS score of < 1% indicates a very small likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The flaw results only in information disclosure and does not grant additional privileges.
OpenCVE Enrichment