๐Ÿ” CVE Alert

CVE-2026-37981

MEDIUM 4.3

Keycloak: org.keycloak.authorization: keycloak: information disclosure via broken access control in user lookup endpoint

CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
10th

A flaw was found in Keycloak. A broken access control vulnerability in the Account Resources user lookup endpoint allows a remote authenticated user, who owns at least one User-Managed Access (UMA) resource, to enumerate and harvest personally identifiable information (PII) for all realm users. By sending crafted requests with arbitrary usernames or email values, the endpoint returns full profile objects for unrelated users. This leads to broad profile-level information disclosure.

CWE CWE-1220
Vendor red hat
Product red hat build of keycloak 26.4
Published May 19, 2026
Last Updated May 20, 2026
Stay Ahead of the Next One

Get instant alerts for red hat red hat build of keycloak 26.4

Be the first to know when new medium vulnerabilities affecting red hat red hat build of keycloak 26.4 are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None

Affected Versions

Red Hat / Red Hat build of Keycloak 26.4
All versions affected
Red Hat / Red Hat build of Keycloak 26.4
All versions affected
Red Hat / Red Hat build of Keycloak 26.4
All versions affected
Red Hat / Red Hat build of Keycloak 26.4.12
All versions affected

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
access.redhat.com: https://access.redhat.com/errata/RHSA-2026:19596 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:19597 access.redhat.com: https://access.redhat.com/security/cve/CVE-2026-37981 bugzilla.redhat.com: https://bugzilla.redhat.com/show_bug.cgi?id=2455326

Credits

Red Hat would like to thank XavLimSG for reporting this issue.