CVE-2026-9088
LOWKeycloak: keycloak: information disclosure due to user profile permission bypass
Title source: cnaDescription
A flaw was found in org.keycloak.services. An administrator with delegated access to read group memberships and users can bypass user profile permissions by accessing the group members endpoint. This allows the administrator to view user attributes that are explicitly configured to be denied, leading to information disclosure.
References (4)
Core 4
Core References
Vdb Entry, X_Refsource_Redhat vdb-entry
x_refsource_redhat
https://access.redhat.com/security/cve/CVE-2026-9088
Issue Tracking, X_Refsource_Redhat issue-tracking
x_refsource_redhat
RHBZ#2480179
https://bugzilla.redhat.com/show_bug.cgi?id=2480179
Vendor Advisory vendor-advisory
x_refsource_redhat
RHSA-2026:25097
https://access.redhat.com/errata/RHSA-2026:25097
Vendor Advisory vendor-advisory
x_refsource_redhat
RHSA-2026:25098
https://access.redhat.com/errata/RHSA-2026:25098
Scores
CVSS v3
2.7
EPSS
0.0032
EPSS Percentile
23.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-1220
Status
published
Products (4)
Red Hat/Red Hat Build of Keycloak
Red Hat/Red Hat build of Keycloak 26.6
26.6-6
Red Hat/Red Hat build of Keycloak 26.6
26.6.3-3
Red Hat/Red Hat build of Keycloak 26.6.3
Published
Jun 05, 2026
Tracked Since
Jun 05, 2026