Количество 4
Количество 4
CVE-2026-7500
When Keycloak is started with `--features-disabled=account,account-api`, the Account REST API is only partially disabled. Five endpoints under the versioned path `/account/v1alpha1` remain fully functional — including both read and write operations — because they lack the `checkAccountApiEnabled()` gate that correctly blocks four other endpoints in the same REST service class. The user needs to have permissions to use the API.
CVE-2026-7500
When Keycloak is started with `--features-disabled=account,account-api`, the Account REST API is only partially disabled. Five endpoints under the versioned path `/account/v1alpha1` remain fully functional — including both read and write operations — because they lack the `checkAccountApiEnabled()` gate that correctly blocks four other endpoints in the same REST service class. The user needs to have permissions to use the API.
CVE-2026-7500
When Keycloak is started with `--features-disabled=account,account-api ...
GHSA-hm32-hfmw-rhvg
Keycloak has a Forced Browsing issue
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-7500 When Keycloak is started with `--features-disabled=account,account-api`, the Account REST API is only partially disabled. Five endpoints under the versioned path `/account/v1alpha1` remain fully functional — including both read and write operations — because they lack the `checkAccountApiEnabled()` gate that correctly blocks four other endpoints in the same REST service class. The user needs to have permissions to use the API. | CVSS3: 5.4 | 0% Низкий | 3 месяца назад | |
CVE-2026-7500 When Keycloak is started with `--features-disabled=account,account-api`, the Account REST API is only partially disabled. Five endpoints under the versioned path `/account/v1alpha1` remain fully functional — including both read and write operations — because they lack the `checkAccountApiEnabled()` gate that correctly blocks four other endpoints in the same REST service class. The user needs to have permissions to use the API. | CVSS3: 5.4 | 0% Низкий | 3 месяца назад | |
CVE-2026-7500 When Keycloak is started with `--features-disabled=account,account-api ... | CVSS3: 5.4 | 0% Низкий | 3 месяца назад | |
GHSA-hm32-hfmw-rhvg Keycloak has a Forced Browsing issue | CVSS3: 5.4 | 0% Низкий | 3 месяца назад |
Уязвимостей на страницу