exploit-intel.com Keycloak Admin API Flaw Allows Unauthorized Group Access
Article Content
- •CVE-2026-97311 allows unauthorized access to group information in Keycloak.
- •Delegated administrators can bypass security restrictions due to improper permission checks.
- •Immediate patching or access restrictions are recommended to mitigate risks.
A vulnerability identified as CVE-2026-97311 in the Admin REST API of Keycloak permits delegated administrators with basic privileges to access detailed information about all groups associated with a specific role. This flaw arises from improper checks for group visibility permissions, allowing unauthorized visibility into groups that should be restricted. The CVSS score assigned to this vulnerability is 4.3, categorizing it as medium severity. Currently, there is no evidence of public proof-of-concept exploitation or active exploitation in the wild. Organizations using affected versions of Keycloak are urged to apply the patch immediately or restrict API access to trusted administrators. The vulnerability was reported to Red Hat on September 22, 2026, and made public on the same day. Administrators are advised to audit API access logs to identify any unauthorized exposure of group information.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Following this threat?
Track CVE-2026-97311 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in F5 BIG-IP APM Exploited for Remote Code Execution F5 Networks has reported a critical vulnerability in its BIG-IP Access Policy Manager (APM), tracked as CVE-2026-94127, which is being actively exploited in the wild. The flaw allows unauthenticated attackers to execute remote code on systems configured with both an APM access policy and an OAuth profile. This…
Massive Network of AI Proxy Servers Used for Malicious Activities Uncovered Security researchers from Team Cymru have identified over 10,000 proxy servers in China facilitating malicious AI activities. These servers, termed 'transfer stations,' are primarily used to bypass geographic restrictions and conduct model distillation attacks against frontier AI models. The infrastructure allows…