A security vulnerability (CVE-2026-18571) has been identified in the Keycloak server used by the Identity and Access Management (IAM) component of Service Virtualization (DevTest).
When Fine-Grained Admin Permissions V2 (FGAP V2) is enabled, a flaw exists in the user creation component. This issue allows a sub-administrator with permission to create users to add those users to any group—including groups the sub-administrator is not authorized to manage. This could lead to unauthorized access to sensitive information or elevated privileges for the newly created users.
Vulnerability Details
Impact Unauthorized access to sensitive information or potential privilege escalation for newly created users due to improper group assignment during the user creation process.
Broadcom Engineering has confirmed this vulnerability will be addressed in the upcoming Service Virtualization (DevTest) 10.9.3 release.
Remediation Steps