Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-9088

Опубликовано: 05 июн. 2026
Источник: redhat
CVSS3: 2.7
EPSS Низкий

Описание

A flaw was found in org.keycloak.services. An administrator with delegated access to read group memberships and users can bypass user profile permissions by accessing the group members endpoint. This allows the administrator to view user attributes that are explicitly configured to be denied, leading to information disclosure.

Отчет

Low: A flaw in Keycloak allows administrators with delegated access to read group memberships and users to bypass user profile permissions. This enables the viewing of user attributes that are configured to be denied, impacting data confidentiality for specific administrative roles.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Дополнительная информация

Статус:

Low
Дефект:
CWE-1220
https://bugzilla.redhat.com/show_bug.cgi?id=2480179keycloak: Keycloak: Information disclosure due to user profile permission bypass

EPSS

Процентиль: 27%
0.00348
Низкий

2.7 Low

CVSS3

Связанные уязвимости

CVSS3: 2.7
nvd
около 2 месяцев назад

A flaw was found in org.keycloak.services. An administrator with delegated access to read group memberships and users can bypass user profile permissions by accessing the group members endpoint. This allows the administrator to view user attributes that are explicitly configured to be denied, leading to information disclosure.

CVSS3: 2.7
debian
около 2 месяцев назад

A flaw was found in org.keycloak.services. An administrator with deleg ...

CVSS3: 2.7
github
около 2 месяцев назад

Keycloak: Information disclosure due to user profile permission bypass

EPSS

Процентиль: 27%
0.00348
Низкий

2.7 Low

CVSS3