CVE-2026-18571 vulnerability in Red Hat Products
Published on August 2, 2026
Keycloak-services: keycloak-services: fgap v2 group assignment bypass during user creation
A flaw was found in the user creation component of Keycloak when Fine-Grained Admin Permissions V2 (FGAP V2) is enabled. This issue allows a sub-administrator with permission to create users to add those users to any group, even groups the sub-administrator is not authorized to manage. This could lead to unauthorized access to sensitive information or elevated privileges for the newly created users.
Vulnerability Analysis
CVE-2026-18571 can be exploited with network access, and requires user privileges. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to be very high.
Timeline
Reported to Red Hat.
Made public.
Weakness Type
What is an AuthZ Vulnerability?
The software does not perform an authorization check when an actor attempts to access a resource or perform an action.
CVE-2026-18571 has been classified to as an AuthZ vulnerability or weakness.
Products Associated with CVE-2026-18571
Want to know whenever a new CVE is published for Red Hat products? stack.watch will email you.