Authorization Flaw in Keycloak Identity and Access Management Solution
CVE-2026-94213
4.9MEDIUM
What is CVE-2026-94213?
A flaw in the Authorization Services of Keycloak can lead to unauthorized access to sensitive user information. The vulnerability occurs in the policy evaluation endpoint, which is intended for administrators to assess the applicability of access policies for specific users. Due to insufficient authorization checks, a delegated administrator with restricted privileges can view comprehensive profiles, including email addresses and security roles of any user in the realm. This flaw poses significant risks to user privacy and data security.