Skip to main content
Vulnerability Database/CVE-2026-97311

CVE-2026-97311: Keycloak Admin REST API Auth Bypass Flaw

CVE-2026-97311 is an authentication bypass flaw in Keycloak Admin REST API that lets delegated administrators view group information beyond their permissions. This article covers technical details, affected versions, security impact, and mitigation strategies.

Published:

CVE-2026-97311 Overview

CVE-2026-97311 is a missing authorization flaw [CWE-862] in the Admin REST API of Keycloak, an open source identity and access management solution. The endpoints that return groups associated with a specific role fail to enforce per-group visibility checks. A delegated administrator holding only basic search privileges can enumerate detailed information about every group assigned to a role, bypassing scope restrictions intended to limit visibility to specific groups.

Critical Impact

Authenticated low-privilege administrators can disclose group membership metadata across the realm, exposing organizational structure and supporting lateral privilege mapping.

Affected Products

  • Keycloak (Admin REST API)
  • Red Hat build of Keycloak
  • Red Hat Single Sign-On based deployments relying on delegated group administration

Discovery Timeline

  • 2026-09-24 - CVE CVE-2026-97311 published to NVD
  • 2026-09-24 - Last updated in NVD database

Technical Details for CVE-2026-97311

Vulnerability Analysis

The flaw resides in the Keycloak Admin REST API endpoints used to list groups bound to a given role. These endpoints return the full set of groups mapped to the role without evaluating whether the caller has view rights on each individual group. Keycloak's fine-grained administrative permission model allows realm owners to restrict a delegated admin to a subset of groups, but the role-to-group lookup path does not consult those per-group ACLs before serializing results.

The exposure is limited to confidentiality. Integrity and availability remain intact, since the endpoints only read group metadata and do not permit modification. However, the disclosed data includes group names, attributes, and hierarchy details that are typically restricted in multi-tenant realms. The vulnerability is tracked as CWE-862: Missing Authorization and carries an EPSS probability of 0.245%.

Root Cause

Keycloak evaluates administrator permissions at the role scope rather than at each returned group. The handler iterates the role's group assignments and returns them directly, skipping the canViewGroup check that other admin endpoints apply. This is a classic authorization gap where a coarse-grained check substitutes for a required object-level check.

Attack Vector

An authenticated delegated administrator with search privileges issues a GET request to the Admin REST API endpoint that returns groups for a role (for example, /admin/realms/{realm}/roles/{role-name}/groups or /admin/realms/{realm}/roles-by-id/{role-id}/groups). The server returns all groups mapped to that role regardless of whether the caller is scoped to view them. No user interaction is required, and the request can be scripted to enumerate groups across every role in the realm.

The vulnerability manifests in the role-group lookup handlers of the Admin REST API. See the Red Hat CVE-2026-97311 Advisory for implementation references.

Detection Methods for CVE-2026-97311

Indicators of Compromise

  • Repeated authenticated GET requests from a single admin principal to /admin/realms/*/roles/*/groups or /admin/realms/*/roles-by-id/*/groups endpoints.
  • Admin audit events showing a delegated administrator retrieving group listings for roles outside their assigned group scope.
  • Unusual volumes of role enumeration followed by group lookups from service or integration accounts.

Detection Strategies

  • Enable Keycloak admin events and monitor ACTION = VIEW entries targeting role-group resources, correlating caller identity against the realm's fine-grained admin permission map.
  • Baseline normal Admin REST API usage per administrator and alert when a principal accesses role-group endpoints at a frequency or breadth inconsistent with their delegated scope.
  • Deploy WAF or API gateway rules that log and rate-limit Admin REST API traversal patterns matching role enumeration followed by group retrieval.

Monitoring Recommendations

  • Forward Keycloak admin and user event streams to a centralized SIEM with retention sufficient for post-incident scope analysis.
  • Review service account tokens with the view-realm or query-groups roles to confirm they are not being used from unexpected network locations.
  • Audit delegated admin role assignments quarterly and verify that users mapped to restricted group scopes have not accessed out-of-scope data.

How to Mitigate CVE-2026-97311

Immediate Actions Required

  • Apply the Keycloak and Red Hat build of Keycloak updates referenced in the Red Hat CVE-2026-97311 Advisory as soon as they are available for your distribution.
  • Inventory accounts holding query-groups, view-realm, or custom delegated admin roles, and remove assignments that are not operationally required.
  • Review admin event logs for the past 90 days for unauthorized access to role-group endpoints and treat disclosed group data as compromised.

Patch Information

Red Hat has published vendor guidance under the Red Hat CVE-2026-97311 Advisory. Upgrade to the fixed Keycloak release noted in the advisory. The fix enforces per-group visibility checks on the role-to-group lookup endpoints so results are filtered to groups the caller is authorized to view.

Workarounds

  • Restrict access to the Admin REST API at the network layer so only trusted administrative networks can reach /admin/realms/* endpoints.
  • Avoid granting the query-groups or broad role-view permissions to delegated administrators until the patched release is deployed.
  • Where delegated administration is not required, consolidate administration under full realm admins and disable fine-grained permissions as an interim control.
bash
# Example: restrict Admin REST API exposure at a reverse proxy (nginx)
location /admin/ {
    allow 10.10.0.0/24;   # admin jump network
    deny all;
    proxy_pass http://keycloak_upstream;
}

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.