CVE-2026-37978
published 2026-05-19CVE-2026-37978: A flaw was found in Keycloak. A low-privilege administrator with the 'view-clients' role can exploit this by invoking the 'evaluate-scopes' Admin API endpoints…
PriorityP431medium4.9CVSS 3.1
AVNACLPRHUINSUCHINAN
EPSS
0.40%
32.1th percentile
A flaw was found in Keycloak. A low-privilege administrator with the 'view-clients' role can exploit this by invoking the 'evaluate-scopes' Admin API endpoints with an arbitrary user ID (userId) parameter. This vulnerability allows for cross-role personally identifiable information (PII) leakage, enabling unauthorized visibility into user identities and authorizations across the realm. Exploitation is possible remotely via network access to the Admin API.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | build_of_keycloak | < 26.4.12 | 26.4.12 |
| rhbk | keycloak-rhel9 | — | — |
CVSS provenance
nvdv3.14.9MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
vendor_redhat4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Keycloak: Information Disclosure via evaluate-scopes Admin API
ghsa·2026-05-19
CVE-2026-37978 [MEDIUM] CWE-639 Keycloak: Information Disclosure via evaluate-scopes Admin API
Keycloak: Information Disclosure via evaluate-scopes Admin API
A flaw was found in Keycloak. A low-privilege administrator with the 'view-clients' role can exploit this by invoking the 'evaluate-scopes' Admin API endpoints with an arbitrary user ID (userId) parameter. This vulnerability allows for cross-role personally identifiable information (PII) leakage, enabling unauthorized visibility into user identities and authorizations across the realm. Exploitation is possible remotely via network access to the Admin API.
GHSA
GHSA-rrv7-3mqf-hxfr: A flaw was found in Keycloak
ghsa_unreviewed·2026-05-19
CVE-2026-37978 [MEDIUM] CWE-639 GHSA-rrv7-3mqf-hxfr: A flaw was found in Keycloak
A flaw was found in Keycloak. A low-privilege administrator with the 'view-clients' role can exploit this by invoking the 'evaluate-scopes' Admin API endpoints with an arbitrary user ID (userId) parameter. This vulnerability allows for cross-role personally identifiable information (PII) leakage, enabling unauthorized visibility into user identities and authorizations across the realm. Exploitation is possible remotely via network access to the Admin API.
Red Hat
keycloak: org.keycloak.services: Keycloak: Information Disclosure via evaluate-scopes Admin API
vendor_redhat·2026-05-19·CVSS 4.9
CVE-2026-37978 [MEDIUM] CWE-639 keycloak: org.keycloak.services: Keycloak: Information Disclosure via evaluate-scopes Admin API
keycloak: org.keycloak.services: Keycloak: Information Disclosure via evaluate-scopes Admin API
A flaw was found in Keycloak. A low-privilege administrator with the 'view-clients' role can exploit this by invoking the 'evaluate-scopes' Admin API endpoints with an arbitrary user ID (userId) parameter. This vulnerability allows for cross-role personally identifiable information (PII) leakage, enabling unauthorized visibility into user identities and authorizations across the realm. Exploitation is possible remotely via network access to the Admin API.
Statement: This is a Moderate impact vulnerability affecting Red Hat Build of Keycloak (RHBK). A low-privilege administrator with the `view-clients` role can exploit the `evaluate-scopes` Admin API endpoints to disclose sensitive user profile
No detection rules found.
No public exploits indexed.
2026-05-19
Published