Description
A flaw was found in the default-groups REST endpoint and realm representation of Keycloak. This component is responsible for managing groups that are automatically assigned to new users within a realm. The issue allows a delegated administrator with realm-viewing permissions to see the names and identifiers of hidden default groups, even if they lack the specific permissions to view those groups. This can lead to the exposure of sensitive organizational structures or internal group names.
Published: 2026-07-17
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw resides in the default-groups REST endpoint and realm representation of Keycloak. A delegated administrator who only has realm‑viewing permissions can retrieve the names and identifiers of hidden default groups, even though those groups are intended to remain invisible. This disclosure can reveal internal group names and organizational structures that were presumed not to be exposed. The weakness is an information disclosure caused by improper access control.

Affected Systems

Affected products include Red Hat Build of Keycloak, Red Hat Single Sign‑On 7, Red Hat JBoss Enterprise Application Platform Expansion Pack, and Red Hat Data Grid 8. There is no specific version range listed by the CNA, so administrators should review all deployed instances of these components for the presence of this flaw.

Risk and Exploitability

Based on the description, it is inferred that the likely attack vector is network access to the default‑groups REST API using a delegated administrator with realm‑viewing privileges. The CVSS score of 4.3 indicates moderate severity, and the EPSS score of less than 1% reflects a low probability of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. Attackers require network access to the REST API and a delegated administrative role with realm‑viewing privileges; no elevated or authenticated privileges beyond that are necessary. Once the endpoint is accessed, the attacker receives enumeration of hidden default groups without further action, making this a straightforward disclosure vector.

Generated by OpenCVE AI on August 3, 2026 at 02:45 UTC.

Remediation

Vendor Workaround

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.


OpenCVE Recommended Actions

  • Deploy the latest Red Hat update that includes the Keycloak fix as soon as it becomes available.
  • Restrict delegated administrators to only the permissions they need; remove realm‑viewing rights from users who do not require group visibility.
  • Reassess your group configuration so that hidden default groups are not essential for business processes, and document any groups that must remain hidden.
  • Enable and review audit logs for group enumeration requests to detect potential misuse of the default‑groups endpoint.
  • No workaround is available per Red Hat; rely on applying the vendor patch and following the guidance provided.

Generated by OpenCVE AI on August 3, 2026 at 02:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 29 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Tue, 28 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Redhat build Of Keycloak
Redhat data Grid
Redhat jboss Enterprise Application Platform Expansion Pack
Vendors & Products Redhat build Of Keycloak
Redhat data Grid
Redhat jboss Enterprise Application Platform Expansion Pack

Wed, 22 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Tue, 21 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200

Sat, 18 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Fri, 17 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 17 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Description A flaw was found in the default-groups REST endpoint and realm representation of Keycloak. This component is responsible for managing groups that are automatically assigned to new users within a realm. The issue allows a delegated administrator with realm-viewing permissions to see the names and identifiers of hidden default groups, even if they lack the specific permissions to view those groups. This can lead to the exposure of sensitive organizational structures or internal group names.
Title Keycloak-services: keycloak-services: realm default-group reads disclose hidden groups under fgap v2
First Time appeared Redhat
Redhat build Keycloak
Redhat jboss Data Grid
Redhat jbosseapxp
Redhat red Hat Single Sign On
CPEs cpe:/a:redhat:build_keycloak:
cpe:/a:redhat:jboss_data_grid:8
cpe:/a:redhat:jbosseapxp
cpe:/a:redhat:red_hat_single_sign_on:7
Vendors & Products Redhat
Redhat build Keycloak
Redhat jboss Data Grid
Redhat jbosseapxp
Redhat red Hat Single Sign On
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Redhat Build Keycloak Build Of Keycloak Data Grid Jboss Data Grid Jboss Enterprise Application Platform Expansion Pack Jbosseapxp Red Hat Single Sign On
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-07-21T16:53:07.924Z

Reserved: 2026-07-17T14:54:36.323Z

Link: CVE-2026-16108

cve-icon Vulnrichment

Updated: 2026-07-17T17:20:07.293Z

cve-icon NVD

No data.

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-07-15T07:21:48Z

Links: CVE-2026-16108 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T03:00:04Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor