Keycloak Patches Flaw That Let Restricted Admins Peek at Users Outside Their Scope
A broken access control bug (CVE-2026-17059) in Keycloak’s Admin REST API allowed administrators with limited privileges to pull personal data on users outside their assigned scope. The issue is fixed in version 26.7.0, but it’s a reminder that access checks need to be consistent across every API path.
Itagora tiene in archivio titolo e sommario per la ricerca interna. Il testo completo resta sulla fonte. Il link in uscita non invia referrer.