PT-2026-55550 · Red Hat · Keycloak

·

CVE-2026-14614

·

Published

2026-07-03

·

Updated

2026-08-25

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Keycloak (affected versions not specified)
Description A flaw exists in the ClientResource component of the admin services when Fine-Grained Admin Permissions (FGAP) v2 is enabled. This issue allows a delegated administrator with limited control over specific clients to attach or remove hidden client scopes they are not authorized to manage. This could enable an attacker to inject unauthorized data or permissions into security tokens issued to end-users, potentially leading other applications to grant higher access levels than intended.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

IDOR

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-KEYCLOAK-2026-14614
CVE-2026-14614

Affected Products

Keycloak