Impact
The flaw resides in the default-groups REST endpoint and realm representation of Keycloak. A delegated administrator who only has realm‑viewing permissions can retrieve the names and identifiers of hidden default groups, even though those groups are intended to remain invisible. This disclosure can reveal internal group names and organizational structures that were presumed not to be exposed. The weakness is an information disclosure caused by improper access control.
Affected Systems
Affected products include Red Hat Build of Keycloak, Red Hat Single Sign‑On 7, Red Hat JBoss Enterprise Application Platform Expansion Pack, and Red Hat Data Grid 8. There is no specific version range listed by the CNA, so administrators should review all deployed instances of these components for the presence of this flaw.
Risk and Exploitability
Based on the description, it is inferred that the likely attack vector is network access to the default‑groups REST API using a delegated administrator with realm‑viewing privileges. The CVSS score of 4.3 indicates moderate severity, and the EPSS score of less than 1% reflects a low probability of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. Attackers require network access to the REST API and a delegated administrative role with realm‑viewing privileges; no elevated or authenticated privileges beyond that are necessary. Once the endpoint is accessed, the attacker receives enumeration of hidden default groups without further action, making this a straightforward disclosure vector.
OpenCVE Enrichment