SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-17059

MEDIUM · CVSS 6.5 EPSS 0.20%

Source: NVD + CISA KEV + EPSS · Published 2026-07-24 · Last synced 2026-08-23

CyberRota Analysis

AI-Generated

A vulnerability in the role-users endpoint of the Keycloak identity and access management solution allows restricted administrators to access private user information, including names and email addresses, without proper permissions. This flaw could lead to unauthorized disclosure of sensitive data, impacting user privacy and security. Organizations using Keycloak should prioritize addressing this issue to safeguard user information and maintain compliance with data protection regulations.

CVE
CVE-2026-17059
Severity
MEDIUM
CVSS
6.5
EPSS
0.20%

Original NVD Description

A flaw was found in the role-users endpoint of the keycloak-services library, which is the core component of the Keycloak identity and access management solution. The issue occurs because the system fails to check if an administrator has permission to view individual users when listing members of a role. This allows a restricted administrator to see private information, such as names and email addresses, for users they should not be able to access.

Related CVEs

Other vulnerabilities affecting the same vendor(s)