What is CVE-2026-18571?
A flaw in Keycloak's user creation component, when Fine-Grained Admin Permissions V2 (FGAP V2) is enabled, allows a sub-administrator with user creation rights to add users to any group, even those outside their management scope. This could lead to privilege escalation and requires immediate patching on affected systems.
Azərbaycanca: Keycloak-in Fine-Grained Admin Permissions V2 funksiyasında aşkar edilən bu qüsur, istifadəçi yaratmaq icazəsi olan sub-administratora səlahiyyəti olmadığı qruplara belə istifadəçi əlavə etməyə imkan verir. Bu, imtiyazların yüksəldilməsinə səbəb ola bilər. FGAP V2 aktiv olan sistemlərdə dərhal yamaq tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
Who is affected by the CVE-2026-18571 flaw in Keycloak?
Systems that have Fine-Grained Admin Permissions V2 (FGAP V2) enabled and where sub-administrators have user creation rights are affected.
What risk can arise if CVE-2026-18571 is exploited?
A sub-administrator could add users to groups outside their management scope, which may lead to privilege escalation.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.