CVE-2026-14614
MEDIUM
5.4
CVSS 3.1
Description
A flaw was found in the ClientResource component of Keycloak's admin services when Fine-Grained Admin Permissions (FGAP) v2 is enabled. This issue allows a delegated administrator, who should only have limited control over specific clients, to attach or remove hidden client scopes that they are not authorized to see or manage. As a result, an attacker could inject unauthorized data or permissions into the security tokens issued to end-users, potentially tricking other applications into granting higher levels of access than intended.
Metadata
Severity & Metrics
5.4
MEDIUM CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Affected products (6)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| Red Hat | Red Hat Build of Keycloak | — | — |
| Red Hat | Red Hat Build of Keycloak | — | — |
| Red Hat | Red Hat Build of Keycloak | — | — |
| Red Hat | Red Hat Data Grid 8 | — | — |
| Red Hat | Red Hat JBoss Enterprise Application Platform Expansion Pack | — | — |
| Red Hat | Red Hat Single Sign-On 7 | — | — |
CVSS scores (1)
| Score | Severity | Version | Source | Vector |
|---|---|---|---|---|
| 5.4 | MEDIUM | 3.1 | cna | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N |
References (2)