Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 4

Количество 4

redhat логотип

CVE-2026-9088

3 месяца назад

A flaw was found in org.keycloak.services. An administrator with delegated access to read group memberships and users can bypass user profile permissions by accessing the group members endpoint. This allows the administrator to view user attributes that are explicitly configured to be denied, leading to information disclosure.

CVSS3: 2.7
EPSS: Низкий
nvd логотип

CVE-2026-9088

3 месяца назад

A flaw was found in org.keycloak.services. An administrator with delegated access to read group memberships and users can bypass user profile permissions by accessing the group members endpoint. This allows the administrator to view user attributes that are explicitly configured to be denied, leading to information disclosure.

CVSS3: 2.7
EPSS: Низкий
debian логотип

CVE-2026-9088

3 месяца назад

A flaw was found in org.keycloak.services. An administrator with deleg ...

CVSS3: 2.7
EPSS: Низкий
github логотип

GHSA-6g26-7cx5-mrrg

3 месяца назад

Keycloak: Information disclosure due to user profile permission bypass

CVSS3: 2.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2026-9088

A flaw was found in org.keycloak.services. An administrator with delegated access to read group memberships and users can bypass user profile permissions by accessing the group members endpoint. This allows the administrator to view user attributes that are explicitly configured to be denied, leading to information disclosure.

CVSS3: 2.7
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-9088

A flaw was found in org.keycloak.services. An administrator with delegated access to read group memberships and users can bypass user profile permissions by accessing the group members endpoint. This allows the administrator to view user attributes that are explicitly configured to be denied, leading to information disclosure.

CVSS3: 2.7
0%
Низкий
3 месяца назад
debian логотип
CVE-2026-9088

A flaw was found in org.keycloak.services. An administrator with deleg ...

CVSS3: 2.7
0%
Низкий
3 месяца назад
github логотип
GHSA-6g26-7cx5-mrrg

Keycloak: Information disclosure due to user profile permission bypass

CVSS3: 2.7
0%
Низкий
3 месяца назад

Уязвимостей на страницу