Information Disclosure Vulnerability in Keycloak Services by Red Hat
CVE-2026-9088
2.7LOW
Key Information:
- Vendor
Red Hat
- Vendor
- CVE Published:
- 5 June 2026
What is CVE-2026-9088?
A critical flaw exists in Keycloak services, where an administrator with delegated access can bypass user profile permissions by accessing the group members endpoint. This vulnerability allows the administrator to retrieve user attributes that are explicitly set to be hidden, leading to potential unauthorized disclosure of sensitive user information.
Affected Version(s)
Red Hat build of Keycloak 26.6 26.6.3-3
Red Hat build of Keycloak 26.6 26.6-6
Red Hat build of Keycloak 26.6 26.6-6
References
CVSS V3.1
Score:
2.7
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Hadley So for reporting this issue.