Keycloak Vulnerabilities Expose Sensitive Data and Admin Roles
Article Content
Two critical vulnerabilities were identified in Keycloak, affecting its REST API. CVE-2026-16108 allows unauthorized visibility of hidden default groups by delegated administrators, risking exposure of sensitive organizational structures. CVE-2026-16105 enables attackers to degrade permissions of other administrators by removing critical roles from the built-in admin role. Both vulnerabilities were tracked in a private repository before being disclosed. The flaws affect all versions of Keycloak that utilize the mentioned endpoints. Patches are expected to be released soon, but no active exploitation has been reported yet. Organizations using Keycloak should prioritize applying updates once available to mitigate these risks.
Key Points: • CVE-2026-16108 exposes hidden default groups to unauthorized admins. • CVE-2026-16105 allows role degradation for Keycloak administrators. • Both vulnerabilities are critical and require immediate attention from users.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.