CVE-2026-97311: Missing Authorization in Red Hat Red Hat Build of Keycloak
A flaw was found in the Admin REST API of Keycloak, an identity and access management solution. The endpoints used to retrieve groups associated with a specific role do not properly check for individual group visibility permissions. This allows a delegated administrator with basic search privileges to view detailed information about all groups assigned to a role, bypassing intended security restrictions that should limit their view to specific groups.
AI Analysis
Technical Summary
A missing authorization check in the Admin REST API of Red Hat Build of Keycloak allows delegated administrators with limited privileges to bypass fine-grained visibility controls. Specifically, the API endpoints that retrieve groups associated with a role do not properly enforce individual group visibility permissions, enabling unauthorized disclosure of group metadata and membership information. The vulnerability requires the attacker to already have delegated administrative privileges and does not impact integrity or availability. Red Hat has assessed the severity as moderate and currently has no mitigation or fix that meets their criteria for ease of deployment and applicability.
Potential Impact
An attacker with delegated administrative privileges can bypass intended security restrictions to view detailed information about all groups assigned to a role, including group metadata and membership. This leads to unauthorized disclosure of sensitive group information. The vulnerability does not affect data integrity or availability. Exploitation requires existing delegated admin privileges, limiting the scope of impact.
Mitigation Recommendations
Red Hat currently states that no mitigation is available or that existing options do not meet their criteria for ease of use, deployment, or applicability. Users should monitor the Red Hat advisory for updates. Since exploitation requires delegated administrative privileges, restricting and auditing such privileges may reduce risk. No official fix or patch is currently available.
CVE-2026-97311: Missing Authorization in Red Hat Red Hat Build of Keycloak
Description
A flaw was found in the Admin REST API of Keycloak, an identity and access management solution. The endpoints used to retrieve groups associated with a specific role do not properly check for individual group visibility permissions. This allows a delegated administrator with basic search privileges to view detailed information about all groups assigned to a role, bypassing intended security restrictions that should limit their view to specific groups.
CVSS v3.1
Score 4.3medium
Affected software
Red Hat
Red Hat Build of Keycloak
Red Hat
Red Hat Single Sign-On 7
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
A missing authorization check in the Admin REST API of Red Hat Build of Keycloak allows delegated administrators with limited privileges to bypass fine-grained visibility controls. Specifically, the API endpoints that retrieve groups associated with a role do not properly enforce individual group visibility permissions, enabling unauthorized disclosure of group metadata and membership information. The vulnerability requires the attacker to already have delegated administrative privileges and does not impact integrity or availability. Red Hat has assessed the severity as moderate and currently has no mitigation or fix that meets their criteria for ease of deployment and applicability.
Potential Impact
An attacker with delegated administrative privileges can bypass intended security restrictions to view detailed information about all groups assigned to a role, including group metadata and membership. This leads to unauthorized disclosure of sensitive group information. The vulnerability does not affect data integrity or availability. Exploitation requires existing delegated admin privileges, limiting the scope of impact.
Mitigation Recommendations
Red Hat currently states that no mitigation is available or that existing options do not meet their criteria for ease of use, deployment, or applicability. Users should monitor the Red Hat advisory for updates. Since exploitation requires delegated administrative privileges, restricting and auditing such privileges may reduce risk. No official fix or patch is currently available.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- redhat
- Date Reserved
- 2026-09-24T10:58:09.463Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-97311","vendor":"Red Hat"}]
Threat ID: 6ab51c22f7a7c5410652f61d
Added to database: 09/24/2026, 12:48:34 UTC
Last enriched: 09/24/2026, 13:02:44 UTC
Last updated: 09/25/2026, 03:40:40 UTC
Views: 13
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.