CVE-2026-37981: Keycloak: org.keycloak.authorization: keycloak: information disclosure via broken access control in user lookup endpoint

Published Apr 6, 2026
·
Updated

A flaw was found in Keycloak. A broken access control vulnerability in the Account Resources user lookup endpoint allows a remote authenticated user, who owns at least one User-Managed Access (UMA) resource, to enumerate and harvest personally identifiable information (PII) for all realm users. By sending crafted requests with arbitrary usernames or email values, the endpoint returns full profile objects for unrelated users. This leads to broad profile-level information disclosure.

Other sources

Broken Access Control vulnerability in Keycloak’s Account Resources user lookup endpoint. The flaw is caused by validating only that the UMA resource ID belongs to the caller, without enforcing any relationship between that resource and the user being queried. When a crafted request is sent with arbitrary usernames or email values, the endpoint returns full profile objects (ID, username, name, email, status) for unrelated users. This can be exploited remotely by any authenticated user who owns at least one UMA-managed resource. Attackers can systematically enumerate and harvest PII for all realm users, leading to broad profile-level information disclosure.

Red Hat

Affected Software

2 affected components
maven/org.keycloak.authorization/keycloak
redhat Build Of Keycloak>=26.4<26.4.12

Event History

Apr 6, 2026
Data Sourced
via Red Hat·07:53 AM
DescriptionSeverityAffected Software
May 19, 2026
CVE Published
via MITRE·10:28 AM
Data Sourced
via MITRE·10:28 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:16 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2026-37981?

The severity of CVE-2026-37981 is medium, with a CVSS score of 4.3.

2

What is CVE-2026-37981?

CVE-2026-37981 refers to a broken access control vulnerability in the Keycloak user lookup endpoint that allows information disclosure.

3

How do I fix CVE-2026-37981?

To fix CVE-2026-37981, it is recommended to update to the latest version of Keycloak that addresses this vulnerability.

4

What kind of information is disclosed by CVE-2026-37981?

CVE-2026-37981 allows authenticated users to enumerate and harvest personally identifiable information (PII) for all realm users.

5

Who is affected by CVE-2026-37981?

CVE-2026-37981 affects users of Keycloak who have implemented User-Managed Access (UMA) resources.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203