CVE-2026-94213
Received Received - Intake

Authorization Bypass in Keycloak Exposes User Data

Vulnerability report for CVE-2026-94213, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-21

Last updated on: 2026-09-21

Assigner: redhat-SADP

Description

A flaw was found in the Authorization Services component of Keycloak, an open-source identity and access management solution. The issue occurs in the policy evaluation endpoint, which is used by administrators to test how access policies apply to specific users. Due to missing authorization checks, a delegated administrator with limited viewing privileges can access the full profile and role information of any user in the realm, even if they are not permitted to view user details. This could lead to the exposure of sensitive information such as email addresses and assigned security roles.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-21
Last Modified
2026-09-21
Generated
2026-09-21
AI Q&A
2026-09-21
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
redhat keycloak *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-94213 is an information disclosure vulnerability in Keycloak's Authorization Services policy evaluation endpoint. A delegated administrator with limited privileges can access full user profile and role information of any user in the realm by exploiting missing authorization checks in the endpoint. This allows exposure of sensitive data like email addresses and security roles.

Detection Guidance

To detect this vulnerability, monitor Keycloak's Authorization Services policy evaluation endpoint for unauthorized access attempts. Check logs for requests to the endpoint with userId parameters from delegated administrators lacking view-users permissions. Look for responses containing sensitive user data like email addresses or role mappings.

Impact Analysis

This vulnerability allows attackers with administrative access to read sensitive user data such as email addresses, full names, and role assignments for any user in the realm. Exploitation could lead to unauthorized access to confidential information or resources, potentially causing further security breaches or compliance violations.

Compliance Impact

This vulnerability could lead to unauthorized disclosure of personal data, violating GDPR's data protection principles and HIPAA's privacy rules. Exposure of sensitive user information may result in regulatory fines, legal liabilities, and loss of trust due to non-compliance with data protection requirements.

Mitigation Strategies

Apply the latest Keycloak patches immediately. Restrict access to the policy evaluation endpoint by reviewing and tightening permissions for delegated administrators. Remove unnecessary administrative privileges and monitor for suspicious activity in the Authorization Services component.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-94213. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart