Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Keycloak Security Flaw Exposes User Data Across Boundaries

Keycloak Security Flaw Exposes User Data Across Boundaries

Posted on July 31, 2026 By CWS

Keycloak has recently resolved a critical access control vulnerability that permitted limited administrators to access sensitive user data beyond their authorization levels. This flaw, identified as CVE-2026-17059, posed a significant risk to user privacy by allowing unauthorized access to usernames, email addresses, and other profile information.

Details of the Keycloak Vulnerability

The vulnerability was discovered by Enzo Mongin, a researcher from Escape, and it impacts the Keycloak Admin REST API. It was formally acknowledged by Red Hat on July 24, 2026, and a corrective update, Keycloak version 26.7.0, was released on July 28, 2026.

The issue was located in a specific API endpoint used for listing members assigned to roles: GET /admin/realms/{realm}/roles/{role-name}/users. Restricted administrators, possessing only query-users and view-realm permissions, could exploit this endpoint to obtain comprehensive user data, including usernames, email addresses, and account statuses.

Implications and Risks

Keycloak’s standard user-listing API correctly restricted access, returning empty responses for unauthorized queries. However, the role-members endpoint did not apply the same user-level authorization checks, leading to potential unauthorized data exposure.

This oversight could result in privacy breaches within shared Keycloak environments, particularly affecting accounts designed to have limited directory access, such as support or helpdesk roles.

Remediation and Recommendations

The vulnerability is classified as broken object-level authorization (CWE-639), with a CVSS score of 6.5, indicating a medium risk level. It specifically affects environments where limited admin roles are delegated, highlighting the need for careful access control configurations.

The security patch now enforces per-user visibility checks before returning user records. Deployments using the default permission model, with adminPermissionsEnabled set to false, are primarily affected. Organizations are urged to upgrade to Keycloak version 26.7.0 or later and reassess roles with query-users and view-realm permissions.

Security teams should also evaluate sibling API endpoints to ensure consistent enforcement of access controls, as securing primary routes does not guarantee protection across all pathways.

In conclusion, organizations must promptly update their Keycloak deployments and review their access control policies to safeguard user data effectively.

Cyber Security News Tags:access control, admin permissions, API security, CVE-2026-17059, Cybersecurity, enterprise security, Keycloak, Red Hat, security flaw, system update, user data exposure, user privacy, Vulnerability

Post navigation

Previous Post: AI Dependency in Incident Response Plans
Next Post: AI Security Platform Enhances Automated Penetration Tests

Related Posts

Incident Response Team ShieldForce Partners with AccuKnox to Deliver Zero Trust CNAPP in Latin America Incident Response Team ShieldForce Partners with AccuKnox to Deliver Zero Trust CNAPP in Latin America Cyber Security News
Critical Vulnerability in Android Microsoft Teams Exposed Critical Vulnerability in Android Microsoft Teams Exposed Cyber Security News
New ToneShell Backdoor With New Features Leverage Task Scheduler COM Service for Persistence New ToneShell Backdoor With New Features Leverage Task Scheduler COM Service for Persistence Cyber Security News
Critical Vulnerability in OpenAI Codex Exposes macOS Users Critical Vulnerability in OpenAI Codex Exposes macOS Users Cyber Security News
MacOS Screen Sharing Issue in Microsoft Teams MacOS Screen Sharing Issue in Microsoft Teams Cyber Security News
Microsoft Exchange Online Outage for Users Accessing Email via Exchange Online Methods Microsoft Exchange Online Outage for Users Accessing Email via Exchange Online Methods Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • AI Security Platform Enhances Automated Penetration Tests
  • Keycloak Security Flaw Exposes User Data Across Boundaries
  • AI Dependency in Incident Response Plans
  • Cyber Attacks Hit Central Asia Using New Malware Tools
  • North Korean Cyber Campaign Targets Crypto Wallets

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • AI Security Platform Enhances Automated Penetration Tests
  • Keycloak Security Flaw Exposes User Data Across Boundaries
  • AI Dependency in Incident Response Plans
  • Cyber Attacks Hit Central Asia Using New Malware Tools
  • North Korean Cyber Campaign Targets Crypto Wallets

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark