Description
A flaw was found in the Admin REST API of Keycloak, an identity and access management solution. The endpoints used to retrieve groups associated with a specific role do not properly check for individual group visibility permissions. This allows a delegated administrator with basic search privileges to view detailed information about all groups assigned to a role, bypassing intended security restrictions that should limit their view to specific groups.
Published: 2026-09-24
Score: 4.3 Medium
EPSS: n/a
KEV: No
Impact: Information Disclosure
Action: Assess Impact
AI Analysis

Impact

A flaw in the Admin REST API of Keycloak allows a delegated administrator with basic search privileges to see detailed information about all groups assigned to a role, because the endpoint that retrieves those groups does not enforce group‑visibility permissions. This bypasses the intended restriction that only certain groups should be viewable by a given administrator. The impact is the exposure of potentially sensitive group data, which could enable an attacker to map the organization’s group structure and privilege model. The flaw is a classic authorization bypass reflected in CWE‑862.

Affected Systems

The affected products are Red Hat Build of Keycloak and Red Hat Single Sign‑On 7. No specific version numbers are provided, so any deployment of these products that contains the vulnerable Admin REST API is at risk.

Risk and Exploitability

The CVSS score of 4.3 indicates moderate severity, and the EPSS score is not available, so a quantitative estimate of exploitation likelihood is not provided. The vulnerability is not listed in the CISA KEV catalog, suggesting no documented large‑scale exploits. The likely attack vector is via the exposed Admin REST API, inferred because the description talks about role‑group retrieval through API calls. An attacker would need to be a delegated administrator with search privileges, a role that is reasonably common in administrative delegations, which makes the condition of exploitation feasible in many installations.

Generated by OpenCVE AI on September 24, 2026 at 13:05 UTC.

Remediation

Vendor Workaround

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.


OpenCVE Recommended Actions

  • Apply any available Keycloak update from Red Hat when a patch is released for this issue; keep the product up to date.
  • No official workaround is available; rely on the vendor patch and follow Red Hat’s security advisory guidance.
  • Limit delegated administrators to the minimum set of privileges required for their tasks, ensuring they cannot exercise the role‑group retrieval function unless necessary.
  • Configure logging and alerting for Admin REST API calls that expose role‑group information so you can detect unauthorized or excessive access events.

Generated by OpenCVE AI on September 24, 2026 at 13:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 24 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Description A flaw was found in the Admin REST API of Keycloak, an identity and access management solution. The endpoints used to retrieve groups associated with a specific role do not properly check for individual group visibility permissions. This allows a delegated administrator with basic search privileges to view detailed information about all groups assigned to a role, bypassing intended security restrictions that should limit their view to specific groups.
Title Keycloak-services: keycloak-services: admin rest api role-groups endpoint discloses groups without authorization
First Time appeared Redhat
Redhat build Keycloak
Redhat red Hat Single Sign On
Weaknesses CWE-862
CPEs cpe:/a:redhat:build_keycloak:
cpe:/a:redhat:red_hat_single_sign_on:7
Vendors & Products Redhat
Redhat build Keycloak
Redhat red Hat Single Sign On
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Redhat Build Keycloak Red Hat Single Sign On
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-24T12:31:31.053Z

Reserved: 2026-09-24T10:58:09.463Z

Link: CVE-2026-97311

cve-icon Vulnrichment

Updated: 2026-09-24T12:31:27.883Z

cve-icon NVD

Status : Received

Published: 2026-09-24T12:17:13.943

Modified: 2026-09-24T13:17:19.850

Link: CVE-2026-97311

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-24T13:15:18Z

Weaknesses