Secure Bulletin Navigating the cyber sea with knowledge
Home > Tag > Access Control
#Access Control

Keycloak Patches Flaw That Let Restricted Admins Peek at Users Outside Their Scope

1 August 2026  |  dark6  |  Vulnerability

A broken access control bug (CVE-2026-17059) in Keycloak's Admin REST API allowed administrators with limited privileges to pull personal data on users outside their assigned scope. The issue...

>> read more

SonicWall SonicOS Flaws Let Attackers Bypass Firewall Access Controls and Trigger Denial of Service

30 April 2026  |  dark6  |  Vulnerability

SonicWall has patched three vulnerabilities in SonicOS — CVE-2026-0204 (CVSS 8.0), CVE-2026-0205, and CVE-2026-0206 — affecting Generation 6, 7, and 8 firewalls. Discovered by CrowdStrike, the flaws allow...

>> read more