logo

Keycloak Flaw Exposes Users’ Personal Data to Restricted Admins

ID: bc848049-26f3-5b3b-b33d-4f6b5835b5d8

STIX ID: report--bc848049-26f3-5b3b-b33d-4f6b5835b5d8

Feed Name: GBHackers

Threat Score
55/100

Date Published: 2026-07-31

Date Updated: 2026-08-01

Author: Divya

...
...

A broken access control vulnerability (CVE-2026-17059) in Keycloak's Admin REST API allowed restricted administrators to enumerate users via GET /admin/realms/{realm}/roles/{role-name}/users, exposing usernames, email addresses, first/last names and account/email verification status. The issue affects realms using the default administration permission model (adminPermissionsEnabled=false), was assigned CVSS 3.1 6.5 (Medium), and was fixed in Keycloak 26.7.0; administrators are advised to upgrade and review accounts granted query-users and view-realm permissions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.