Junglewise Threat Intelligence

CVE-2026-37978: Keycloak information disclosure in evaluate-scopes Admin API

CVE-2026-37978 · Severity: medium · CVSS 4.9 · Published 2026-05-19

Technologies: Red Hat build of Keycloak, Red Hat build of Keycloak, org.keycloak:keycloak-services (Maven), Keycloak. Vendors: Red Hat, Maven, Keycloak.

Executive brief

Keycloak is an open-source identity and access management solution used to secure modern applications and services. A security flaw allows a low-privileged administrator to view sensitive personal information and authorization details of any user in the system. This could lead to the exposure of user identities and roles across the entire organization, potentially aiding further targeted attacks.

Technical details

An authorization bypass (CWE-639) exists in Keycloak's 'evaluate-scopes' Admin API endpoints. The vulnerability stems from the application accepting an arbitrary 'userId' parameter while only validating that the requester has the 'view-clients' role, failing to perform necessary user-view permission checks (e.g., auth.users().requireView()). By invoking these endpoints, an attacker with limited administrative privileges can generate example tokens containing full profile and role data for any user ID. This allows for cross-role personally identifiable information (PII) leakage and unauthorized visibility into user identities and authorizations. The issue is patched in Keycloak version 26.6.2 and Red Hat build of Keycloak 26.4.12.

Affected products

  • Keycloak Keycloak < 26.6.2
  • Red Hat Red Hat build of Keycloak < 26.4.12

Timeline

  • 2026-04-06: disclosed: Initial report in Red Hat Bugzilla
  • 2026-05-19: advisory: GitHub and NVD advisory published
  • 2026-05-20: patched: Red Hat security advisory issued

References

Related threats