Keycloak Flaw Exposes Users’ Personal Data to Restricted Admins

A broken access control vulnerability in Keycloak could allow unauthorized administrator accounts to access users’ personal information. This issue, tracked as CVE-2026-17059, affects the Keycloak Admin REST API and was discovered by researcher Enzo Mongin from Escape Research, also known as Orionexe. The vulnerability was reported to the Keycloak team on July 18, 2026, acknowledged […]

This article has been indexed from GBHackers Security | #1 Globally Trusted Cyber Security News Platform

Read the original article: