PT-2026-60802 · Red Hat · Keycloak

CVE-2026-16108

·

Published

2026-07-17

·

Updated

2026-08-31

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Keycloak (affected versions not specified)
Description A flaw exists in the realm representation and the 'default-groups' REST endpoint, which manages groups automatically assigned to new users within a realm. A delegated administrator with realm-viewing permissions can view the names and identifiers of hidden default groups without having the required specific permissions. This may result in the exposure of internal group names or sensitive organizational structures.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-KEYCLOAK-2026-16108
CVE-2026-16108

Affected Products

Keycloak