๐Ÿ” CVE Alert

CVE-2026-9088

LOW 2.7

Keycloak: keycloak: information disclosure due to user profile permission bypass

CVSS Score
2.7
EPSS Score
0.0%
EPSS Percentile
1th

A flaw was found in org.keycloak.services. An administrator with delegated access to read group memberships and users can bypass user profile permissions by accessing the group members endpoint. This allows the administrator to view user attributes that are explicitly configured to be denied, leading to information disclosure.

CWE CWE-1220
Vendor red hat
Product red hat build of keycloak
Published Jun 5, 2026
Last Updated Jun 5, 2026
Stay Ahead of the Next One

Get instant alerts for red hat red hat build of keycloak

Be the first to know when new low vulnerabilities affecting red hat red hat build of keycloak are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None

Affected Versions

Red Hat / Red Hat Build of Keycloak
All versions affected

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
access.redhat.com: https://access.redhat.com/security/cve/CVE-2026-9088 bugzilla.redhat.com: https://bugzilla.redhat.com/show_bug.cgi?id=2480179

Credits

Red Hat would like to thank Hadley So for reporting this issue.