THREAT OPS › Threat News › [NVD] CVE-2026-15945 (MEDIUM 4.3) — A flaw was found in the group search functionality of the Keycloak server's administrative API. When Fine-Grained Admin Permissions (FGAP) v2 is enabled, a delegated administrator can bypass access restrictions to view parent groups they are not authorized to see. By searching fo
[NVD] CVE-2026-15945 (MEDIUM 4.3) — A flaw was found in the group search functionality of the Keycloak server's administrative API. When Fine-Grained Admin Permissions (FGAP) v2 is enabled, a delegated administrator can bypass access restrictions to view parent groups they are not authorized to see. By searching fo
CVE-2026-15945 CVSS: 4.3 MEDIUM Published: 2026-07-16T18:16:42.693
A flaw was found in the group search functionality of the Keycloak server's administrative API. When Fine-Grained Admin Permissions (FGAP) v2 is enabled, a delegated administrator can bypass access restrictions to view parent groups they are not authorized to see. By searching for a child group they have permission to view, the sy
Indicators of compromise
- CVE-2026-15945cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-15945