Insufficient Granularity of Access Control in Keycloak - CVE-2026-37981

 

Insufficient Granularity of Access Control in Keycloak - CVE-2026-37981

Published: September 10, 2026


Vulnerability identifier: #VU148954
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-37981
CWE-ID: CWE-1220
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose personally identifiable information for realm users.

The vulnerability exists due to insufficient granularity of access control in the Keycloak Account Resources user lookup endpoint when handling crafted requests containing arbitrary usernames or email values. A remote user can send crafted requests to enumerate realm users and retrieve full profile objects for unrelated users to disclose personally identifiable information for realm users.

Exploitation requires ownership of at least one User-Managed Access (UMA) resource.


Affected software

Keycloak
Red Hat build of Keycloak

How to mitigate CVE-2026-37981

Install security update from vendor's website.

Keycloak - addressed in versions 26.4.12, 26.6.2
Red Hat build of Keycloak - update to 26.4.12

External References

Related Security Bulletins