THREAT OPS › Threat News › [NVD] CVE-2026-18571 (MEDIUM 6.6) — A flaw was found in the user creation component of Keycloak when Fine-Grained Admin Permissions V2 (FGAP V2) is enabled. This issue allows a sub-administrator with permission to create users to add those users to any group, even groups the sub-administrator is not authorized to m
[NVD] CVE-2026-18571 (MEDIUM 6.6) — A flaw was found in the user creation component of Keycloak when Fine-Grained Admin Permissions V2 (FGAP V2) is enabled. This issue allows a sub-administrator with permission to create users to add those users to any group, even groups the sub-administrator is not authorized to m
CVE-2026-18571 CVSS: 6.6 MEDIUM Published: 2026-08-02T06:16:42.000
A flaw was found in the user creation component of Keycloak when Fine-Grained Admin Permissions V2 (FGAP V2) is enabled. This issue allows a sub-administrator with permission to create users to add those users to any group, even groups the sub-administrator is not authorized to manage. This could lead to unauthorized access to sen
Indicators of compromise
- CVE-2026-18571cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-18571