CVE-2026-18571
Keycloak-services: keycloak-services: fgap v2 group assignment bypass during user creation
Record summary
CVE-2026-18571 has a selected CVSS score of 6.6 (medium).
Description
A flaw was found in the user creation component of Keycloak when Fine-Grained Admin Permissions V2 (FGAP V2) is enabled. This issue allows a sub-administrator with permission to create users to add those users to any group, even groups the sub-administrator is not authorized to manage. This could lead to unauthorized access to sensitive information or elevated privileges for the newly created users.
Exploitation context
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 3, 2026 · Source: CVE List
Affected products and versions
6| Product | Source | Version range | Status |
|---|---|---|---|
Default status: affected | CVE List | Version data not supplied | |
Red Hat Build of KeycloakBrowse Red Hat / Red Hat Build of Keycloakrhbk-keycloak-rhel9/rhbk-keycloak-rhel9Default status: affected | CVE List | Version data not supplied | |
Red Hat Build of KeycloakBrowse Red Hat / Red Hat Build of Keycloakrhbk-openshift-rhel9/rhbk-openshift-rhel9Default status: affected | CVE List | Version data not supplied | |
Default status: unaffected | CVE List | Version data not supplied | |
Red Hat JBoss Enterprise Application Platform Expansion PackBrowse Red Hat / Red Hat JBoss Enterprise Application Platform Expansion Packkeycloak-servicesDefault status: unaffected | CVE List | Version data not supplied | |
Default status: unaffected | CVE List | Version data not supplied | |