CVE-2026-37981
published 2026-05-19CVE-2026-37981: A flaw was found in Keycloak. A broken access control vulnerability in the Account Resources user lookup endpoint allows a remote authenticated user, who owns…
PriorityP429medium4.3CVSS 3.1
AVNACLPRLUINSUCLINAN
EPSS
0.37%
29.3th percentile
A flaw was found in Keycloak. A broken access control vulnerability in the Account Resources user lookup endpoint allows a remote authenticated user, who owns at least one User-Managed Access (UMA) resource, to enumerate and harvest personally identifiable information (PII) for all realm users. By sending crafted requests with arbitrary usernames or email values, the endpoint returns full profile objects for unrelated users. This leads to broad profile-level information disclosure.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | build_of_keycloak | >= 26.4 < 26.4.12 | 26.4.12 |
| rhbk | keycloak-rhel9 | — | — |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
keycloak: org.keycloak.authorization: Keycloak: Information disclosure via broken access control in user lookup endpoint
vendor_redhat·2026-05-19·CVSS 4.3
CVE-2026-37981 [MEDIUM] CWE-1220 keycloak: org.keycloak.authorization: Keycloak: Information disclosure via broken access control in user lookup endpoint
keycloak: org.keycloak.authorization: Keycloak: Information disclosure via broken access control in user lookup endpoint
A flaw was found in Keycloak. A broken access control vulnerability in the Account Resources user lookup endpoint allows a remote authenticated user, who owns at least one User-Managed Access (UMA) resource, to enumerate and harvest personally identifiable information (PII) for all realm users. By sending crafted requests with arbitrary usernames or email values, the endpoint returns full profile objects for unrelated users. This leads to broad profile-level information disclosure.
Statement: Moderate: This vulnerability in Red Hat Build of Keycloak (RHBK) allows an authenticated user to bypass access controls in the Account Resources user lookup endpoint. By sending c
GHSA
Keycloak Account Resources user lookup contains broken access control
ghsa·2026-05-19
CVE-2026-37981 [MEDIUM] CWE-1220 Keycloak Account Resources user lookup contains broken access control
Keycloak Account Resources user lookup contains broken access control
Keycloak's Account Resources user lookup endpoint allows a remote authenticated user, who owns at least one User-Managed Access (UMA) resource, to enumerate and harvest personally identifiable information (PII) for all realm users. By sending crafted requests with arbitrary usernames or email values, the endpoint returns full profile objects for unrelated users. This leads to broad profile-level information disclosure.
GHSA
GHSA-933f-rg6j-f46p: A flaw was found in Keycloak
ghsa_unreviewed·2026-05-19
CVE-2026-37981 [MEDIUM] CWE-1220 GHSA-933f-rg6j-f46p: A flaw was found in Keycloak
A flaw was found in Keycloak. A broken access control vulnerability in the Account Resources user lookup endpoint allows a remote authenticated user, who owns at least one User-Managed Access (UMA) resource, to enumerate and harvest personally identifiable information (PII) for all realm users. By sending crafted requests with arbitrary usernames or email values, the endpoint returns full profile objects for unrelated users. This leads to broad profile-level information disclosure.
No detection rules found.
No public exploits indexed.
2026-05-19
Published