Authorization bypass through user-controlled key in Keycloak - CVE-2026-37978
Published: September 10, 2026
Vulnerability details
The vulnerability allows a remote user to disclose personally identifiable information.
The vulnerability exists due to authorization bypass through a user-controlled key in the evaluate-scopes Admin API endpoints when invoking the endpoints with an arbitrary user ID parameter. A remote privileged user can submit an arbitrary user ID to view user identities and authorizations across the realm.
The issue affects administrators assigned the view-clients role.
Affected software
Red Hat build of Keycloak
How to mitigate CVE-2026-37978
Red Hat build of Keycloak - update to 26.4.12