Keycloak Vulnerability Exposes User Names and Email Addresses Across Admin Boundaries
ID: dc1a5260-352d-51ed-8d35-99cc3c357470
STIX ID: report--dc1a5260-352d-51ed-8d35-99cc3c357470
Feed Name: cybersecurityNews.com
Keycloak addressed a broken object-level authorization flaw (CVE-2026-17059) in the role-members API (GET /admin/realms/{realm}/roles/{role-name}/users) that allowed restricted administrators with only query-users and view-realm permissions to obtain full user records (usernames, emails, names, account and email verification status). The issue, rated CVSS 6.5, affects deployments using the default permission model and was fixed in Keycloak 26.7.0; administrators should upgrade and audit accounts granted those privileges.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
