Authorization bypass through user-controlled key in Red Hat build of Keycloak - CVE-2026-14209
Published: September 11, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive user information.
The vulnerability exists due to a missing authorization check in the BruteForceUsersResource component of the admin UI extension when handling requests to the brute-force-user endpoint. A remote user can request a target user\'s profile through the brute-force-user endpoint to disclose sensitive user information.
Fine-Grained Admin Permissions v2 must be enabled, and exploitation requires knowledge of the target user\'s ID.