CVE-2026-9088

LOW

Keycloak: keycloak: information disclosure due to user profile permission bypass

Title source: cna
STIX 2.1

Description

A flaw was found in org.keycloak.services. An administrator with delegated access to read group memberships and users can bypass user profile permissions by accessing the group members endpoint. This allows the administrator to view user attributes that are explicitly configured to be denied, leading to information disclosure.

References (4)

Core 4
Core References
Vdb Entry, X_Refsource_Redhat vdb-entry x_refsource_redhat
https://access.redhat.com/security/cve/CVE-2026-9088
Issue Tracking, X_Refsource_Redhat issue-tracking x_refsource_redhat
RHBZ#2480179
https://bugzilla.redhat.com/show_bug.cgi?id=2480179
Vendor Advisory vendor-advisory x_refsource_redhat
RHSA-2026:25097
https://access.redhat.com/errata/RHSA-2026:25097
Vendor Advisory vendor-advisory x_refsource_redhat
RHSA-2026:25098
https://access.redhat.com/errata/RHSA-2026:25098

Scores

CVSS v3 2.7
EPSS 0.0032
EPSS Percentile 23.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-1220
Status published
Products (4)
Red Hat/Red Hat Build of Keycloak
Red Hat/Red Hat build of Keycloak 26.6 26.6-6
Red Hat/Red Hat build of Keycloak 26.6 26.6.3-3
Red Hat/Red Hat build of Keycloak 26.6.3
Published Jun 05, 2026
Tracked Since Jun 05, 2026