VDB

GCVE-110-NCSC-2026-326

GCVE-110-NCSC-2026-326
Advisory PublishedCVSS 8.1/10
Vulnetix · Advisory published August 25, 2026
A Moderate severity vulnerability in Keycloak's admin interface with FGAP v2 enabled allows certain administrators to view metadata of hidden groups due to missing permission checks on role-to-group mappings in the RoleContainerResource component.

Weaknesses (CWE)

CWE-341Predictable from Observable StateCWE-639Authorization Bypass Through User-Controlled KeyCWE-640Weak Password Recovery Mechanism for Forgotten PasswordCWE-770Allocation of Resources Without Limits or ThrottlingCWE-915Improperly Controlled Modification of Dynamically-Determined Object AttributesCWE-863Incorrect Authorization

Risk Scores

CVSS 3.1
8.1/10
High · CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

Affected Products

VendorProductVersionsPlatforms
Red Hatvers:unknown/*
Keycloakvers:unknown/*

References

advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory

Browse GCVE Records

867 records in the GCVE database · Updated September 2, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›