Keycloak has addressed a broken access control vulnerability that could allow restricted administrators to access usernames, email addresses, and other profile information belonging to users outside their permitted scope. This issue, tracked as CVE-2026-17059, affects the Keycloak Admin REST API and was discovered by Escape researcher Enzo Mongin, known as Orionexe. Red Hat published the CVE on July 24, 2026, and Keycloak remediated the flaw on July 28 with the release of Keycloak version 26.7.0. The vulnerability exists in the endpoint used to list members assigned to a specific role: GET /admin/realms/{realm}/roles/{role-name}/users A restricted administrator with only the query-users and view-realm permissions could call...
Læs hele artiklen hos kilden.
Kommentarer (0)
Ingen kommentarer ennå. Bli den første til å kommentere!