Keycloak Vulnerability Exposes User Names and Email Addresses Across Admin Boundaries

Keycloak has addressed a broken access control vulnerability that could allow restricted administrators to access usernames, email addresses, and other profile information belonging to users outside their permitted scope. This issue, tracked as CVE-2026-17059, affects the Keycloak Admin REST API and was discovered by Escape researcher Enzo Mongin, known as Orionexe. Red Hat published the […]

This article has been indexed from Cyber Security News

Read the original article: