Authorization bypass through user-controlled key in Keycloak - CVE-2026-17059

 

Authorization bypass through user-controlled key in Keycloak - CVE-2026-17059

Published: July 24, 2026 / Updated: September 5, 2026


Vulnerability identifier: #VU146972
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-17059
CWE-ID: CWE-639
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose private user information.

The vulnerability exists due to improper access control in the role-users endpoint of the keycloak-services library when listing members of a role. A remote user can request role membership listings without permission to view the individual users to disclose private user information.

Disclosed information may include user names and email addresses.


Affected software

Keycloak

How to mitigate CVE-2026-17059

Install security update from vendor's website.

Keycloak - update to 26.7.3

External References

Related Security Bulletins