Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-7500

Опубликовано: 30 апр. 2026
Источник: redhat
CVSS3: 5.4
EPSS Низкий

Описание

When Keycloak is started with --features-disabled=account,account-api, the Account REST API is only partially disabled. Five endpoints under the versioned path /account/v1alpha1 remain fully functional — including both read and write operations — because they lack the checkAccountApiEnabled() gate that correctly blocks four other endpoints in the same REST service class. The user needs to have permissions to use the API.

Отчет

This Moderate impact flaw in Keycloak allows authenticated users to bypass the intended disablement of the account and account-api features when Keycloak is started with --features-disabled=account,account-api. This bypass enables unauthorized read and write operations on specific account endpoints, despite the configuration aiming to restrict such access.

Меры по смягчению последствий

To reduce the attack surface, restrict network access to the Keycloak server's administration and API endpoints to trusted networks or hosts. This limits the ability of unauthorized users to interact with the server and potentially exploit this improper access control vulnerability. If the Keycloak service is reloaded or restarted, ensure that firewall rules or network access controls remain in effect.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-425
https://bugzilla.redhat.com/show_bug.cgi?id=2464126org.keycloak.keycloak-services: Improper Access Control on Keycloak Server when the account Account API feature is disabled

EPSS

Процентиль: 14%
0.00232
Низкий

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.4
nvd
3 месяца назад

When Keycloak is started with `--features-disabled=account,account-api`, the Account REST API is only partially disabled. Five endpoints under the versioned path `/account/v1alpha1` remain fully functional — including both read and write operations — because they lack the `checkAccountApiEnabled()` gate that correctly blocks four other endpoints in the same REST service class. The user needs to have permissions to use the API.

CVSS3: 5.4
debian
3 месяца назад

When Keycloak is started with `--features-disabled=account,account-api ...

CVSS3: 5.4
github
3 месяца назад

Keycloak has a Forced Browsing issue

EPSS

Процентиль: 14%
0.00232
Низкий

5.4 Medium

CVSS3