CVE-2026-17059 is a broken object-level authorization vulnerability in Keycloak's Admin REST API with a CVSS score of 6.5, classified as Medium. This flaw allows restricted administrators to access usernames, email addresses, and other profile information belonging to users outside their permitted scope. The issue affects the endpoint used to list members assigned to a specific role, which enforces only broad role-viewing and user-query permissions without applying the same per-user authorization filter as the primary user-listing endpoint. A restricted administrator with query-users and view-realm permissions can call this endpoint to obtain full user records for members of roles they were authorized to view, exposing information such as usernames, email addresses, first and last names, account status, and email verification status. This creates a privacy risk in shared Keycloak realms, particularly where helpdesk-style accounts may be intentionally restricted from browsing the entire user directory. Exploitation requires an authenticated but deliberately limited administrator account, making this relevant for organizations that delegate partial Keycloak administration to support teams or business units.
We recommend you to update Keycloak to version 26.7.0 or later.[/subscribe_to_unlock_form]
CVE-2026-17059 is a broken object-level authorization vulnerability in Keycloak's Admin REST API with a CVSS score of 6.5, classified as Medium. This flaw allows restricted administrators to access usernames, email addresses, and other profile information belonging to users outside their permitted scope. The issue affects the endpoint used to list members assigned to a specific role, which enforces only broad role-viewing and user-query permissions without applying the same per-user authorization filter as the primary user-listing endpoint. A restricted administrator with query-users and view-realm permissions can call this endpoint to obtain full user records for members of roles they were authorized to view, exposing information such as usernames, email addresses, first and last names, account status, and email verification status. This creates a privacy risk in shared Keycloak realms, particularly where helpdesk-style accounts may be intentionally restricted from browsing the entire user directory. Exploitation requires an authenticated but deliberately limited administrator account, making this relevant for organizations that delegate partial Keycloak administration to support teams or business units.
We recommend you to update Keycloak to version 26.7.0 or later.[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]