logo

Escape Research team found a PII disclosure in Keycloak. It’s now CVE-2026-17059.

ID: c18d0e7d-2b8f-5a87-a8b0-4333d57eb27c

STIX ID: report--c18d0e7d-2b8f-5a87-a8b0-4333d57eb27c

Feed Name: Security Boulevard

Threat Score
50/100

Date Published: 2026-07-31

Date Updated: 2026-07-31

Author: Enzo Mongin

...
...

Escape Research disclosed CVE-2026-17059: a broken access-control/PII disclosure in Keycloak where GET /admin/realms/{realm}/roles/{role-name}/users returns full user records (username, email, first/last name, enabled and email-verified state) to an account with only query-users + view-realm on realms using the default admin permission model (adminPermissionsEnabled = false). The report includes root-cause code excerpts showing a missing per-user visibility filter, a self-contained PoC, affected versions, a Responsible Disclosure timeline (reported July 18 2026, CVE published July 24, fixed July 28 in Keycloak 26.7.0), and mitigation details.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.