Description
A flaw was found in the user creation component of Keycloak when Fine-Grained Admin Permissions V2 (FGAP V2) is enabled. This issue allows a sub-administrator with permission to create users to add those users to any group, even groups the sub-administrator is not authorized to manage. This could lead to unauthorized access to sensitive information or elevated privileges for the newly created users.
Published: 2026-08-02
Score: 6.6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Keycloak’s user creation module permits a sub-administrator authorized to create users to add those users to any group when Fine-Grained Admin Permissions V2 is active. The defect allows unauthorized group membership, enabling the new users to obtain access to resources for which they were not intended and potentially read or modify sensitive data.

Affected Systems

Red Hat Build of Keycloak, Red Hat Data Grid 8, Red Hat JBoss Enterprise Application Platform Expansion Pack, Red Hat Single Sign-On 7. The flaw applies to systems running these products with FGAP V2 enabled; specific version ranges are not listed in the CNA data.

Risk and Exploitability

The vulnerability has a CVSS score of 6.6 and an EPSS of less than 1%, indicating low but non-zero exploitation probability, and is not present in the CISA KEV list. The likely attack path involves a privileged sub-administrator exploiting the user creation workflow; no additional prerequisites are described beyond FGAP V2 being enabled.

Generated by OpenCVE AI on August 3, 2026 at 09:29 UTC.

Remediation

Vendor Workaround

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.


OpenCVE Recommended Actions

  • Disable Fine-Grained Admin Permissions V2 if it is not required for your deployment.
  • Restrict sub-administrator roles so they cannot create users or manage groups, ensuring the 'create users' permission is not paired with group assignment rights.
  • Check Red Hat’s security advisories for an authoritative patch or update that addresses this flaw and deploy it as soon as it becomes available.

Generated by OpenCVE AI on August 3, 2026 at 09:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sun, 02 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Redhat build Of Keycloak
Redhat data Grid
Redhat jboss Enterprise Application Platform Expansion Pack
Redhat single Sign-on
Vendors & Products Redhat build Of Keycloak
Redhat data Grid
Redhat jboss Enterprise Application Platform Expansion Pack
Redhat single Sign-on

Sun, 02 Aug 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Sun, 02 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description A flaw was found in the user creation component of Keycloak when Fine-Grained Admin Permissions V2 (FGAP V2) is enabled. This issue allows a sub-administrator with permission to create users to add those users to any group, even groups the sub-administrator is not authorized to manage. This could lead to unauthorized access to sensitive information or elevated privileges for the newly created users.
Title Keycloak-services: keycloak-services: fgap v2 group assignment bypass during user creation
First Time appeared Redhat
Redhat build Keycloak
Redhat jboss Data Grid
Redhat jbosseapxp
Redhat red Hat Single Sign On
Weaknesses CWE-862
CPEs cpe:/a:redhat:build_keycloak:
cpe:/a:redhat:jboss_data_grid:8
cpe:/a:redhat:jbosseapxp
cpe:/a:redhat:red_hat_single_sign_on:7
Vendors & Products Redhat
Redhat build Keycloak
Redhat jboss Data Grid
Redhat jbosseapxp
Redhat red Hat Single Sign On
References
Metrics cvssV3_1

{'score': 6.6, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Redhat Build Keycloak Build Of Keycloak Data Grid Jboss Data Grid Jboss Enterprise Application Platform Expansion Pack Jbosseapxp Red Hat Single Sign On Single Sign-on
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-08-03T19:52:10.720Z

Reserved: 2026-08-02T05:15:31.359Z

Link: CVE-2026-18571

cve-icon Vulnrichment

Updated: 2026-08-03T19:52:06.684Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-02T06:16:42.000

Modified: 2026-08-07T18:30:35.053

Link: CVE-2026-18571

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-07-30T10:29:12Z

Links: CVE-2026-18571 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T09:30:17Z

Weaknesses