GHSA-rrv7-3mqf-hxfrMediumCVSS 4.9

A flaw was found in Keycloak. A low-privilege administrator with the 'view-clients' role can...

Published
May 19, 2026
Last Modified
May 20, 2026

🔗 CVE IDs covered (1)

📋 Description

A flaw was found in Keycloak. A low-privilege administrator with the 'view-clients' role can exploit this by invoking the 'evaluate-scopes' Admin API endpoints with an arbitrary user ID (userId) parameter. This vulnerability allows for cross-role personally identifiable information (PII) leakage, enabling unauthorized visibility into user identities and authorizations across the realm. Exploitation is possible remotely via network access to the Admin API.

🔗 References (6)