Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-18571

A flaw was found in the user creation component of Keycloak when Fine-Grained Admin Permissions V2 (FGAP V2) is enabled. This issue allows a sub-administrator with permission to create users to add those users to any group, even groups the sub-administrator is not authorized to manage. This could lead to unauthorized access to sensitive information or elevated privileges for the newly created users.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 15.7%
CVSS Severity
CVSS v3 Score 6.6
Products affected by CVE-2026-18571


Contact Us

Shodan ® - All rights reserved