Crypto Ticker:
sysadmin from Cyber Security News

Keycloak Vulnerability Exposes User Names and Email Addresses Across Admin Boundaries

Abinaya
6 hours ago
5 Views
0 Comments
Keycloak Vulnerability Exposes User Names and Email Addresses Across Admin Boundaries

Keycloak has addressed a broken access control vulnerability that could allow restricted administrators to access usernames, email addresses, and other profile information belonging to users outside their permitted scope. This issue, tracked as CVE-2026-17059, affects the Keycloak Admin REST API and was discovered by Escape researcher Enzo Mongin, known as Orionexe. Red Hat published the CVE on July 24, 2026, and Keycloak remediated the flaw on July 28 with the release of Keycloak version 26.7.0. The vulnerability exists in the endpoint used to list members assigned to a specific role: GET /admin/realms/{realm}/roles/{role-name}/users A restricted administrator with only the query-users and view-realm permissions could call...

Read the full article at the source.

Join the discussion — comment, vote, and submit links.

Register
Was this helpful?
Share:

Comments (0)

Please login or register to join the discussion

No comments yet. Be the first to comment!