Authorization bypass through user-controlled key in Keycloak - CVE-2026-17059
Published: July 24, 2026 / Updated: September 5, 2026
Vulnerability details
The vulnerability allows a remote user to disclose private user information.
The vulnerability exists due to improper access control in the role-users endpoint of the keycloak-services library when listing members of a role. A remote user can request role membership listings without permission to view the individual users to disclose private user information.
Disclosed information may include user names and email addresses.