Beveiligingsadvies

CVE-2026-37978

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-05-19 10:52:29
Laatst bijgewerkt 2026-05-20 16:08:53
Toegewezen door redhat
CVSS-score 4.9
Status PUBLISHED

Beschrijving

A flaw was found in Keycloak. A low-privilege administrator with the 'view-clients' role can exploit this by invoking the 'evaluate-scopes' Admin API endpoints with an arbitrary user ID (userId) parameter. This vulnerability allows for cross-role personally identifiable information (PII) leakage, enabling unauthorized visibility into user identities and authorizations across the realm. Exploitation is possible remotely via network access to the Admin API.