๐Ÿ” CVE Alert

CVE-2026-17059

MEDIUM 6.5

Keycloak-services: keycloak-services: information disclosure via role-users endpoint bypasses per-user view filter

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th

A flaw was found in the role-users endpoint of the keycloak-services library, which is the core component of the Keycloak identity and access management solution. The issue occurs because the system fails to check if an administrator has permission to view individual users when listing members of a role. This allows a restricted administrator to see private information, such as names and email addresses, for users they should not be able to access.

CWE CWE-639
Vendor red hat
Product red hat build of keycloak
Published Jul 24, 2026
Last Updated Jul 24, 2026
Stay Ahead of the Next One

Get instant alerts for red hat red hat build of keycloak

Be the first to know when new medium vulnerabilities affecting red hat red hat build of keycloak are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

Red Hat / Red Hat Build of Keycloak
All versions affected
Red Hat / Red Hat Build of Keycloak
All versions affected
Red Hat / Red Hat Build of Keycloak
All versions affected
Red Hat / Red Hat Data Grid 8
All versions affected
Red Hat / Red Hat JBoss Enterprise Application Platform Expansion Pack
All versions affected
Red Hat / Red Hat Single Sign-On 7
All versions affected

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
access.redhat.com: https://access.redhat.com/security/cve/CVE-2026-17059 bugzilla.redhat.com: https://bugzilla.redhat.com/show_bug.cgi?id=2506746

Credits

Red Hat would like to thank Orionexe for reporting this issue.