<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T17:58:40.309194+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-keycloak-2026-14615</id>
    <title>BIT-keycloak-2026-14615 — Keycloak-services: keycloak: fgap v2 parent group children endpoint bypasses per-child view permission filter</title>
    <updated>2026-10-03T17:58:40.384175+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: keycloak</p>
<p>A flaw was found in the Fine-Grained Admin Permissions (FGAP) v2 implementation within Keycloak's administrative services. When FGAP v2 is enabled, the system fails to properly filter child groups based on the caller's specific permissions when requested through a parent group. This allows a delegated administrator to view details of child groups they are not authorized to access directly, including group names, paths, and custom attributes.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-keycloak-2026-14615"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-348746</id>
    <title>EUVD-2026-348746</title>
    <updated>2026-10-03T17:58:40.384243+00:00</updated>
    <content>EUVD-2026-348746</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-348746"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-14615</id>
    <title>fkie_cve-2026-14615</title>
    <updated>2026-10-03T17:58:40.384260+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in the Fine-Grained Admin Permissions (FGAP) v2 implementation within Keycloak's administrative services. When FGAP v2 is enabled, the system fails to properly filter child groups based on the caller's specific permissions when requested through a parent group. This allows a delegated administrator to view details of child groups they are not authorized to access directly, including group names, paths, and custom attributes.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-14615"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-5qq8-h7qh-phfj</id>
    <title>GHSA-5qq8-h7qh-phfj</title>
    <updated>2026-10-03T17:58:40.384285+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in the Fine-Grained Admin Permissions (FGAP) v2 implementation within Keycloak's administrative services. When FGAP v2 is enabled, the system fails to properly filter child groups based on the caller's specific permissions when requested through a parent group. This allows a delegated administrator to view details of child groups they are not authorized to access directly, including group names, paths, and custom attributes.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-5qq8-h7qh-phfj"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:50846</id>
    <title>RHSA-2026:50846 — Red Hat Security Advisory: Red Hat build of Keycloak 26.4.14 Security Update</title>
    <updated>2026-10-03T17:58:40.384303+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>keycloak: Keycloak: Privilege escalation through hardcoded role mapper injection keycloak: org.keycloak.protocol.oidc: HTTP Parameter Pollution in OIDC redirect URI allows response parameter duplication - #GHI-604 keycloak: Keycloak: Security policy bypass in JWE-encrypted request object processing keycloak: Keycloak: Brute-force protection bypass in CIBA flow keycloak-policy-enforcer: Keycloak Policy Enforcer: Authorization bypass via incorrect URI comparison keycloak-admin-ui: keycloak-admin-ui:Admin UI extension brute-force-user endpoint bypasses FGAPv2 user view restrictions keycloak-services: keycloak-services: FGAP v2 client scope assignment bypass via ClientResource keycloak-services: keycloak: FGAP v2 parent group children endpoint bypasses per-child view permission filter keycloak-services: keycloak-services: DCR protocol mapper type-swap policy bypass allows privilege escalation keycloak-services: keycloak-services: Authorization bypass via unnormalized URI matching in PathMatcher keycloak-services: keycloak-services: LDAP entry-DN user search bypasses configured users DN boundary keycloak-services: keycloak-services: Default DCR policy allows role forgery via User Property mappers io.quarkus/quarkus-rest: io.quarkus/quarkus-vertx-http: io.quarkus.resteasy.reactive/resteasy-reactive: Quarkus REST - Unbounded multipart MIME part-header accumulation allows remote OOM denial of service keycloak-services: keycloak-services: SAML IdP-initiated broker login bypasses link…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:50846"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-14615</id>
    <title>UBUNTU-CVE-2026-14615</title>
    <updated>2026-10-03T17:58:40.384353+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:24.04:LTS: python-keycloak, Ubuntu:25.10: python-keycloak</p>
<p>A flaw was found in the Fine-Grained Admin Permissions (FGAP) v2 implementation within Keycloak's administrative services. When FGAP v2 is enabled, the system fails to properly filter child groups based on the caller's specific permissions when requested through a parent group. This allows a delegated administrator to view details of child groups they are not authorized to access directly, including group names, paths, and custom attributes.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-14615"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2198</id>
    <title>WID-SEC-W-2026-2198 — Keycloak: Mehrere Schwachstellen</title>
    <updated>2026-10-03T17:58:40.384377+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Keycloak ausnutzen, um Informationen offenzulegen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren oder erweiterte Berechtigungen zu erlangen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2198"/>
  </entry>
</feed>
