Insufficient Granularity of Access Control Affecting org.keycloak:keycloak-server-spi-private package, versions [,26.6.3)


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.35% (27th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-ORGKEYCLOAK-17220132
  • published7 Jun 2026
  • disclosed5 Jun 2026
  • creditUnknown

Introduced: 5 Jun 2026

CVE-2026-9088  (opens in a new tab)
CWE-1220  (opens in a new tab)

How to fix?

Upgrade org.keycloak:keycloak-server-spi-private to version 26.6.3 or higher.

Overview

org.keycloak:keycloak-server-spi-private is an open source identity and access management solution for modern applications and services.

Affected versions of this package are vulnerable to Insufficient Granularity of Access Control in the getMembers() methods that serve the group members endpoint. An admin user with delegated access to read group memberships and users can read user profile attributes that are explicitly configured to be denied by using their delegated administrative access to expose those values over the group membership API.

CVSS Base Scores

version 4.0
version 3.1