Skip to content
Keycloak Admin API Flaw Allows Unauthorized Group Access

Keycloak Admin API Flaw Allows Unauthorized Group Access

First seen 24 Sep 2026, 18:59 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 24, 2026 at 20:52 UTC
  • •CVE-2026-97311 allows unauthorized access to group information in Keycloak.
  • •Delegated administrators can bypass security restrictions due to improper permission checks.
  • •Immediate patching or access restrictions are recommended to mitigate risks.

A vulnerability identified as CVE-2026-97311 in the Admin REST API of Keycloak permits delegated administrators with basic privileges to access detailed information about all groups associated with a specific role. This flaw arises from improper checks for group visibility permissions, allowing unauthorized visibility into groups that should be restricted. The CVSS score assigned to this vulnerability is 4.3, categorizing it as medium severity. Currently, there is no evidence of public proof-of-concept exploitation or active exploitation in the wild. Organizations using affected versions of Keycloak are urged to apply the patch immediately or restrict API access to trusted administrators. The vulnerability was reported to Red Hat on September 22, 2026, and made public on the same day. Administrators are advised to audit API access logs to identify any unauthorized exposure of group information.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-22
Vulnerability reported to Red Hat
CVE-2026-97311 was reported by Nomit Vyas to Red Hat, prompting an investigation.
cve.threatint.com
2026-09-22
Vulnerability made public
Details of CVE-2026-97311 were published, alerting users to the security risk.
cve.threatint.com
2026-09-24
CVE-2026-97311 published
CVE-2026-97311 was officially published with a CVSS score of 4.3, indicating medium severity.
Feedly

More articles in this cluster (5)

Following this threat?

Track CVE-2026-97311 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed