A vulnerability was found in Red Hat Keycloak, Data Grid, JBoss Enterprise Application Platform and JBoss Single Sign-On. It has been declared as problematic. Affected by this issue is some unknown functionality of the component Administrative API. Such manipulation leads to improper privilege management.

This vulnerability is referenced as CVE-2026-18201. It is possible to launch the attack remotely. No exploit is available.