THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-15945 (MEDIUM 4.3) — A flaw was found in the group search functionality of the Keycloak server's administrative API. When Fine-Grained Admin Permissions (FGAP) v2 is enabled, a delegated administrator can bypass access restrictions to view parent groups they are not authorized to see. By searching fo

[NVD] CVE-2026-15945 (MEDIUM 4.3) — A flaw was found in the group search functionality of the Keycloak server's administrative API. When Fine-Grained Admin Permissions (FGAP) v2 is enabled, a delegated administrator can bypass access restrictions to view parent groups they are not authorized to see. By searching fo

mednvdPublished 2026-07-16

CVE-2026-15945 CVSS: 4.3 MEDIUM Published: 2026-07-16T18:16:42.693

A flaw was found in the group search functionality of the Keycloak server's administrative API. When Fine-Grained Admin Permissions (FGAP) v2 is enabled, a delegated administrator can bypass access restrictions to view parent groups they are not authorized to see. By searching for a child group they have permission to view, the sy

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-15945