
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-14082 is an Improper Access Control vulnerability in the Keycloak Admin REST API that allows information disclosure of sensitive role metadata. A remote authenticated attacker possessing only the built-in role_query-groups permission can retrieve the complete list of realm roles — including administrator-created roles and internal metadata — via insufficient authorization checks on the /admin/realms/{realm}/roles endpoint. The vulnerability affects org.keycloak:keycloak-services versions prior to 26.5.0. It was reported on December 5, 2025, and publicly disclosed on December 10, 2025. It carries a CVSS v3.1 base score of 2.7 (Low) (Github Advisory, Red Hat Bugzilla).
The root cause is classified as CWE-284 (Improper Access Control). The /admin/realms/{realm}/roles endpoint fails to enforce sufficiently granular authorization checks, allowing a user with only the role_query-groups permission to enumerate all realm roles, including their names, IDs, composite status, and container identifiers — data that should require broader administrative privileges. Exploitation requires network access and a valid authenticated session with at least the role_query-groups role; no special tools or complex conditions are needed beyond a standard HTTP GET request to the affected endpoint. The fix was introduced in commit 89a8cdd of the Keycloak repository (Github Advisory, Red Hat Bugzilla).
Successful exploitation results in limited confidentiality impact: an attacker can enumerate realm role names, IDs, composite status, and container identifiers without authorization to view full role details or modify configurations. This information disclosure could allow a restricted attacker to map the privilege structure of a Keycloak deployment and identify high-value roles for targeted privilege-escalation attempts. There is no integrity or availability impact, and the scope is unchanged (Github Advisory, Red Hat Bugzilla).
role_query-groups permission within the target realm.POST /realms/{realm}/protocol/openid-connect/token).GET /admin/realms/{realm}/roles with the Authorization: Bearer <token> header./admin/realms/{realm}/roles from accounts that should not require full role enumeration (e.g., accounts with only role_query-groups permission).LIST or QUERY operations on the roles resource from low-privilege accounts; access logs with high frequency of requests to the roles endpoint from a single user or IP.role_query-groups only) accessing the Admin REST API roles endpoint outside of expected administrative workflows.Upgrade org.keycloak:keycloak-services to version 26.5.0 or later to remediate the vulnerability. Red Hat build of Keycloak users should apply the updates provided in RHSA-2026:6477 (version 26.4.11) and RHSA-2026:6478 (container images for OpenShift). As interim measures, restrict the role_query-groups permission to only trusted administrative accounts, audit existing role assignments, and monitor Admin REST API access logs for anomalous enumeration activity (Github Advisory, RHSA-2026:6477, RHSA-2026:6478).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."