Insufficient Granularity of Access Control in Keycloak - CVE-2026-37981
Published: September 10, 2026
Vulnerability details
The vulnerability allows a remote user to disclose personally identifiable information for realm users.
The vulnerability exists due to insufficient granularity of access control in the Keycloak Account Resources user lookup endpoint when handling crafted requests containing arbitrary usernames or email values. A remote user can send crafted requests to enumerate realm users and retrieve full profile objects for unrelated users to disclose personally identifiable information for realm users.
Exploitation requires ownership of at least one User-Managed Access (UMA) resource.
Affected software
Red Hat build of Keycloak
How to mitigate CVE-2026-37981
Red Hat build of Keycloak - update to 26.4.12