BIT-keycloak-2026-37981

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/keycloak/BIT-keycloak-2026-37981.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-keycloak-2026-37981
Aliases
Published
2026-08-25T11:42:21Z
Modified
2026-09-08T08:48:06Z
Summary
Keycloak: org.keycloak.authorization: keycloak: information disclosure via broken access control in user lookup endpoint
Details

A flaw was found in Keycloak. A broken access control vulnerability in the Account Resources user lookup endpoint allows a remote authenticated user, who owns at least one User-Managed Access (UMA) resource, to enumerate and harvest personally identifiable information (PII) for all realm users. By sending crafted requests with arbitrary usernames or email values, the endpoint returns full profile objects for unrelated users. This leads to broad profile-level information disclosure.

Database specific
{
    "cpes": [
        "cpe:2.3:a:redhat:build_of_keycloak:*:*:*:*:*:*:*:*",
        "cpe:2.3:a:keycloak:keycloak:*:*:*:*:*:*:*:*"
    ],
    "severity": "Medium"
}
References

Affected packages

Bitnami / keycloak

Package

Name
keycloak
Purl
pkg:bitnami/keycloak

Severity

  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
26.4.0
Fixed
26.4.12

Database specific

source
"https://github.com/bitnami/vulndb/tree/main/data/keycloak/BIT-keycloak-2026-37981.json"