CVE-2026-18571Disclosure(redhat / build_of_keycloak)

LOWCVSS 7.2 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw was found in the user creation component of Keycloak when Fine-Grained Admin Permissions V2 (FGAP V2) is enabled. This issue allows a sub-administrator with permission to create users to add those users to any group, even groups the sub-administrator is not authorized to manage. This could lead to unauthorized access to sensitive information or elevated privileges for the newly created users.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • build_of_keycloak

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
build_of_keycloak

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-08-02: 3Technical Details · 2026-08-02: 208-02
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets4 URLs
Full discourse3 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-18571 A flaw was found in the user creation component of Keycloak when Fine-Grained Admin Permissions V2 (FGAP V2) is enabled. This issue allows a sub-administrator with pe… https://www.cve.org/CVERecord?id=CVE-2026-18571 ----- Traducción: Se encontró una fa… http://infoflow.cloud`

    Post summary

    Keycloak's FGAP V2 user creation component has a new flaw that can grant elevated sub‑administrator privileges; no PoC, exploit, or patch details are provided.

    0000045
    96 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-18571 A flaw was found in the user creation component of Keycloak when Fine-Grained Admin Permissions V2 (FGAP V2) is enabled. This issue allows a sub-administrator with pe… https://www.cve.org/CVERecord?id=CVE-2026-18571

    Post summary

    The post announces a new Keycloak vulnerability (CVE‑2026‑18571) that enables sub‑administrators to exploit a flaw in user creation with FGAP V2 enabled, without providing PoC, exploit, or patch details.

    00000532
    57.9K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-18571 Unauthorized Group Assignment in Keycloak Fine-Grained Admin Perm... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-18571 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    The post merely references CVE‑2026‑18571 with a brief title and provides two links, lacking any actionable or technical details.

    00000120
    4.1K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appredhatbuild_of_keycloak---

Explore more