SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-18571

MEDIUM · CVSS 6.6 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-08-02 · Last synced 2026-09-01

CyberRota Analysis

AI-Generated

A vulnerability exists in the user creation component of Keycloak when Fine-Grained Admin Permissions V2 is enabled, allowing sub-administrators to add users to any group, regardless of their permissions. This could result in unauthorized access to sensitive information or elevated privileges for those users. Organizations utilizing Keycloak with FGAP V2 should prioritize addressing this issue to mitigate potential security risks.

CVE
CVE-2026-18571
Severity
MEDIUM
CVSS
6.6
EPSS
0.24%

Original NVD Description

A flaw was found in the user creation component of Keycloak when Fine-Grained Admin Permissions V2 (FGAP V2) is enabled. This issue allows a sub-administrator with permission to create users to add those users to any group, even groups the sub-administrator is not authorized to manage. This could lead to unauthorized access to sensitive information or elevated privileges for the newly created users.

Related CVEs

Other vulnerabilities affecting the same vendor(s)