CVE-2026-7500
MEDIUMOrg.keycloak.keycloak-services: improper access control on keycloak server when the account account api feature is disabled
Title source: cnaDescription
When Keycloak is started with `--features-disabled=account,account-api`, the Account REST API is only partially disabled. Five endpoints under the versioned path `/account/v1alpha1` remain fully functional — including both read and write operations — because they lack the `checkAccountApiEnabled()` gate that correctly blocks four other endpoints in the same REST service class. The user needs to have permissions to use the API.
Scores
CVSS v3
5.4
EPSS
0.0002
EPSS Percentile
5.7%
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-425
Status
published
Products (1)
Red Hat/Red Hat Build of Keycloak
Published
Apr 30, 2026
Tracked Since
Apr 30, 2026