CVE-2026-9088
A flaw was found in org.keycloak.services. An administrator with delegated access to read group memberships and users can bypass user profile permissions by accessing the group members endpoint. This allows the administrator to view user attributes that are explicitly configured to be denied, leading to information disclosure.
Scoring
- Severity
- LOW
- CVSS base score
- 2.7
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
- EPSS probability
- 0.35%
- CWE
- CWE-1220
- Published
- 2026-06-05
- Last modified
- 2026-06-26
Affected products
- Red Hat Red Hat build of Keycloak 26.6
- Red Hat Red Hat build of Keycloak 26.6
- Red Hat Red Hat build of Keycloak 26.6
- Red Hat Red Hat build of Keycloak 26.6
- Red Hat Red Hat build of Keycloak 26.4
- Red Hat Red Hat build of Keycloak 26.4
Weakness type
Related vulnerabilities
- CVE-2026-77480 — SQL Server Elevation of Privilege Vulnerability
- CVE-2026-66814 — Microsoft SQL Server Elevation of Privilege Vulnerability
- CVE-2026-69267 — Windows Connected User Experiences and Telemetry Information Disclosure Vulnerability
- CVE-2026-78216 — AshLua eval read operations can read field-policy-protected fields via aggregates
- CVE-2026-78230 — AshAi aggregate tool can read field-policy-protected fields
- CVE-2026-15431 — HP Support Assistant – Potential Escalation of Privilege
- CVE-2026-78122 — docker-socket-proxy through 0.5.0 Insufficient Access Control Granularity Exposes Container Filesystems
- CVE-2026-40145 — Control protections bypass in BeyondTrust Endpoint Privilege Management (Windows deployment) support utility