Executive brief
Keycloak is an open-source identity and access management solution used to secure modern applications and services. A security flaw was discovered where certain account management features remain active even after an administrator has explicitly disabled them. This could allow an authenticated user with existing API permissions to view or modify account data that the organization intended to restrict, potentially leading to unauthorized profile changes or data exposure.
Technical details
A Direct Request ('Forced Browsing') vulnerability exists in Keycloak's Account REST API. When the application is started with the `--features-disabled=account,account-api` flag, five endpoints under the `/account/v1alpha1` path remain functional for both read and write operations. This occurs because these specific endpoints lack the `checkAccountApiEnabled()` authorization gate used by other endpoints in the same service class. An attacker must be authenticated and possess the necessary user permissions to interact with the API to exploit this flaw. The vulnerability allows for unauthorized access to account management functions that were intended to be administratively disabled. The issue is addressed in Keycloak 26.6.3 and later.
Affected products
- Keycloak Keycloak <= 26.6.1
- Red Hat Red Hat build of Keycloak < 26.6.3
Timeline
- 2026-04-30: disclosed: Initial disclosure and CVE assignment
- 2026-04-30: advisory: GitHub Advisory published
- 2026-05-07: patched: Fix merged into Keycloak main branch
- 2026-06-10: patched: Red Hat released patched version 26.6.3