Secure Bulletin Navigating the cyber sea with knowledge
Home > Tag > Keycloak
#Keycloak

Keycloak Patches Flaw That Let Restricted Admins Peek at Users Outside Their Scope

1 August 2026  |  dark6  |  Vulnerability

A broken access control bug (CVE-2026-17059) in Keycloak's Admin REST API allowed administrators with limited privileges to pull personal data on users outside their assigned scope. The issue...

>> read more