Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 4

Количество 4

redhat логотип

CVE-2026-9088

около 2 месяцев назад

A flaw was found in org.keycloak.services. An administrator with delegated access to read group memberships and users can bypass user profile permissions by accessing the group members endpoint. This allows the administrator to view user attributes that are explicitly configured to be denied, leading to information disclosure.

CVSS3: 2.7
EPSS: Низкий
nvd логотип

CVE-2026-9088

около 2 месяцев назад

A flaw was found in org.keycloak.services. An administrator with delegated access to read group memberships and users can bypass user profile permissions by accessing the group members endpoint. This allows the administrator to view user attributes that are explicitly configured to be denied, leading to information disclosure.

CVSS3: 2.7
EPSS: Низкий
debian логотип

CVE-2026-9088

около 2 месяцев назад

A flaw was found in org.keycloak.services. An administrator with deleg ...

CVSS3: 2.7
EPSS: Низкий
github логотип

GHSA-6g26-7cx5-mrrg

около 2 месяцев назад

Keycloak: Information disclosure due to user profile permission bypass

CVSS3: 2.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2026-9088

A flaw was found in org.keycloak.services. An administrator with delegated access to read group memberships and users can bypass user profile permissions by accessing the group members endpoint. This allows the administrator to view user attributes that are explicitly configured to be denied, leading to information disclosure.

CVSS3: 2.7
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-9088

A flaw was found in org.keycloak.services. An administrator with delegated access to read group memberships and users can bypass user profile permissions by accessing the group members endpoint. This allows the administrator to view user attributes that are explicitly configured to be denied, leading to information disclosure.

CVSS3: 2.7
0%
Низкий
около 2 месяцев назад
debian логотип
CVE-2026-9088

A flaw was found in org.keycloak.services. An administrator with deleg ...

CVSS3: 2.7
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-6g26-7cx5-mrrg

Keycloak: Information disclosure due to user profile permission bypass

CVSS3: 2.7
0%
Низкий
около 2 месяцев назад

Уязвимостей на страницу