CVE-2026-7500

MEDIUM

Org.keycloak.keycloak-services: improper access control on keycloak server when the account account api feature is disabled

Title source: cna
STIX 2.1

Description

When Keycloak is started with `--features-disabled=account,account-api`, the Account REST API is only partially disabled. Five endpoints under the versioned path `/account/v1alpha1` remain fully functional — including both read and write operations — because they lack the `checkAccountApiEnabled()` gate that correctly blocks four other endpoints in the same REST service class. The user needs to have permissions to use the API.

Scores

CVSS v3 5.4
EPSS 0.0002
EPSS Percentile 5.7%
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-425
Status published
Products (1)
Red Hat/Red Hat Build of Keycloak
Published Apr 30, 2026
Tracked Since Apr 30, 2026