Junglewise Threat Intelligence

CVE-2026-94213: Keycloak Authorization Services policy evaluation missing authorization check

CVE-2026-94213 · Severity: medium · CVSS 4.9 · Published 2026-09-21

Technologies: Keycloak. Vendors: Keycloak.

Executive brief

Keycloak is an open-source identity and access management platform used to control who can access applications and data. A flaw in its policy evaluation feature allows delegated administrators with limited permissions to view full user profiles, email addresses, and security roles they should not have access to. An attacker with administrative privileges on a specific client or resource could exploit this to extract sensitive user information from the entire organization.

Technical details

The vulnerability is a missing authorization check (CWE-862) in the Authorization Services policy evaluation endpoint used for testing access policies. An authenticated attacker with high-level administrative privileges on a specific client or resource server can bypass authorization checks to read sensitive user profile data and role mappings they are otherwise restricted from viewing. The attack requires network access and valid administrative credentials; no user interaction is needed.

Affected products

  • Keycloak Keycloak

Timeline

  • 2026-09-21: disclosed

References

Related threats