Keycloak Vulnerabilities Expose Sensitive Data and Admin Roles

Keycloak Vulnerabilities Expose Sensitive Data and Admin Roles

First seen 31 Aug 2026, 16:03 UTC github.com 57.8

Article Content

Browse articles
ThreatCluster

Two critical vulnerabilities were identified in Keycloak, affecting its REST API. CVE-2026-16108 allows unauthorized visibility of hidden default groups by delegated administrators, risking exposure of sensitive organizational structures. CVE-2026-16105 enables attackers to degrade permissions of other administrators by removing critical roles from the built-in admin role. Both vulnerabilities were tracked in a private repository before being disclosed. The flaws affect all versions of Keycloak that utilize the mentioned endpoints. Patches are expected to be released soon, but no active exploitation has been reported yet. Organizations using Keycloak should prioritize applying updates once available to mitigate these risks.

Key Points: • CVE-2026-16108 exposes hidden default groups to unauthorized admins. • CVE-2026-16105 allows role degradation for Keycloak administrators. • Both vulnerabilities are critical and require immediate attention from users.

Timeline

2026-07-17
CVE-2026-16108 published
A flaw in Keycloak's default-groups REST endpoint was disclosed, allowing unauthorized visibility of sensitive groups.
Article 1
2026-07-31
CVE-2026-16105 published
A missing authorization check in Keycloak's admin API was disclosed, enabling role degradation for admins.
Article 2
Recent
Vulnerabilities disclosed
Both CVEs were disclosed on the same day, prompting immediate attention from security professionals.
Article 1