Information Disclosure Vulnerability in Keycloak Services by Red Hat
CVE-2026-9088

2.7LOW

What is CVE-2026-9088?

A critical flaw exists in Keycloak services, where an administrator with delegated access can bypass user profile permissions by accessing the group members endpoint. This vulnerability allows the administrator to retrieve user attributes that are explicitly set to be hidden, leading to potential unauthorized disclosure of sensitive user information.

Affected Version(s)

Red Hat build of Keycloak 26.6 26.6.3-3

Red Hat build of Keycloak 26.6 26.6-6

Red Hat build of Keycloak 26.6 26.6-6

References

CVSS V3.1

Score:
2.7
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Hadley So for reporting this issue.
.