Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-97311— Keycloak-services: keycloak-services: admin rest api role-groups endpoint discloses groups without authorization

Quick assessment

Affected
Red Hat Red Hat Build of Keycloak
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Keycloak(一种身份和访问管理解决方案)的管理员 REST API 中存在一个漏洞。用于检索与特定角色关联的组的端点未正确检查各个组的可见性权限。这导致拥有基本搜索权限的委派管理员能够查看分配到该角色的所有组的详细信息,从而绕过了本应限制其仅查看特定组的预期安全限制。

CVSS 4.3 · Medium EPSS 0.24% · P14
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-97311

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Keycloak-services: keycloak-services: admin rest api role-groups endpoint discloses groups without authorization
Source: CVE Program / CVE List V5
Vulnerability Description
A flaw was found in the Admin REST API of Keycloak, an identity and access management solution. The endpoints used to retrieve groups associated with a specific role do not properly check for individual group visibility permissions. This allows a delegated administrator with basic search privileges to view detailed information about all groups assigned to a role, bypassing intended security restrictions that should limit their view to specific groups.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制缺失
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Red Hat Red Hat Build of Keycloak - cpe:/a:redhat:build_keycloak:
Red Hat Red Hat Build of Keycloak - cpe:/a:redhat:build_keycloak:
Red Hat Red Hat Single Sign-On 7 - cpe:/a:redhat:red_hat_single_sign_on:7

II. Public POCs for CVE-2026-97311

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-97311

请登录查看更多情报信息。

Other References for CVE-2026-97311 (1)

Same Patch Batch · Red Hat · 2026-09-24 · 8 CVEs total

CVE-2026-90959 8.1 HIGH Pulpcore: pulpcore: file:// scheme allowlist bypass in content upload file_url field enabl
CVE-2026-95521 7.8 HIGH Rpm: rpm: shell command injection via macro expansion of source/spec file basenames when i
CVE-2026-95519 7.8 HIGH Rpm: code execution via macro expansion of manifest entries in `rpmgi` (`-q -p` / verify m
CVE-2026-97185 7.8 HIGH Gimp: gimp: out-of-bounds write in gimpressionist plugin via crafted preset file
CVE-2026-94416 6.8 MEDIUM Aap-gateway: aap-gateway: authorization bypass via workload identity token forgery
CVE-2026-97177 6.6 MEDIUM Keycloak-services: keycloak-services: generic user update bypasses denied reset-password p
CVE-2026-97176 4.2 MEDIUM Keycloak-services: keycloak-services: essential acr requirement silently bypassed via cook

IV. Related Vulnerabilities

V. Comments for CVE-2026-97311

No comments yet


Leave a comment