CVE-2026-17059Patch(redhat / build_of_keycloak)

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch redhat build_of_keycloak systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw was found in the role-users endpoint of the keycloak-services library, which is the core component of the Keycloak identity and access management solution. The issue occurs because the system fails to check if an administrator has permission to view individual users when listing members of a role. This allows a restricted administrator to see private information, such as names and email addresses, for users they should not be able to access.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-639

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • build_of_keycloak

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 5 signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-07-31); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
build_of_keycloak

1 version affected across 1 product

Deep dive

Activity timeline5 mentions / 3d
01122Mentions · 2026-07-31: 2Mentions · 2026-08-04: 2Mentions · 2026-08-07: 1Patch / Workaround · 2026-07-31: 2Patch / Workaround · 2026-08-04: 2Patch / Workaround · 2026-08-07: 1Technical Details · 2026-07-31: 2Technical Details · 2026-08-04: 2Technical Details · 2026-08-07: 107-3108-0408-07
Signal classification2 categories
Patch
480.0%
Disclosure
120.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-07-312
Patch2
2026-08-042
Disclosure1Patch1
2026-08-071
Patch1
Full discourse5 posts
  • ArpokratLeg@ArpoLegDep
    Patch

    🔓 O Keycloak gere a autenticação de milhares de organizações. CVE-2026-17059: um administrador deliberadamente restrito pede a lista de utilizadores e recebe um resultado vazio. Pede os membros de um perfil e recebe nomes, apelidos, endereços de email. Os mesmos dados. Duas portas. Só uma estava guardada. Comunicado pela Escape a 18 de julho, publicado pela Red Hat a 24, corrigido a 28. A correção tem uma linha ⚠️ #Cybersecurity #Privacy

    Post summary

    Keycloak CVE-2026-17059 allowed restricted admins to retrieve user data via profile membership; the issue was fixed on July 28 with a single-line patch.

    0003095
    31 followersView on X
  • ArpoDev@ArpoDev
    Disclosure

    🔓 Keycloak gère l'authentification de milliers d'organisations. CVE-2026-17059 : un administrateur volontairement restreint interroge la liste des utilisateurs, il reçoit un tableau vide. Il interroge les membres d'un rôle, il reçoit les noms, les emails, les prénoms. Mêmes données. Deux portes. Une seule était gardée. Signalé par Escape le 18 juillet, publié par Red Hat le 24, corrigé le 28. Le correctif fait une ligne ⚠️ #Cybersecurity #Privacy

    Post summary

    The text announces the discovery of CVE‑2026‑17059 in Keycloak, explains how a restricted admin can gain incomplete or full user data, and reports Red Hat’s advisory and patch timeline.

    10010131
    374 followersView on X
  • iototsecnews@iototsecnews
    Patch

    Keycloak の脆弱性 CVE-2026-17059 が FIX:Admin 境界の破綻とユーザー情報の露出 https://iototsecnews.jp/2026/07/31/keycloak-vulnerability-exposes-user-names-and-email-addresses-across-admin-boundaries/ Keycloak において、認可制御の設計不備に起因する脆弱性 CVE-2026-17059 が公表されました。この問題は、役割ごとの権限確認が特定の API 呼び出し時に正しく適用されない仕組みに起因しています。悪用された場合、限定的な権限しか持たないアカウントであっても、本来アクセスできないユーザーの氏名や連絡先などを取得できる恐れがあります。対応策として、修正済みの最新バージョンへの更新や管理アカウントの権限設定の点検が有効です。システムを安全に利用するためにも、認可機能の状態を確認し、適切なアップデートを実施することが推奨されます。 #CVE202617059 #Keycloak #Vulnerability

    Post summary

    The article announces Keycloak CVE-2026-17059, explaining a role‑based authorization flaw that could expose user names and contact details, and recommends applying the latest patch and reviewing admin permissions.

    01000163
    505 followersView on X
  • TECHEPAGES@techepages
    Patch

    🚨 Keycloak patches broken access control flaw (CVE-2026-17059, CVSS 6.5) Keycloak has patched a broken access control vulnerability (CVE-2026-17059, CVSS 6.5) affecting the Admin REST API. Restricted administrators holding only query-users and view-realm permissions could retrieve full user profile data — including emails and names — via the role-members endpoint, bypassing restrictions correctly enforced on the primary users API. Root cause: RoleContainerResource.getUsersInRole returned user representations without per-user authorization checks. Fixed in Keycloak 26.7.0.

    Post summary

    Keycloak discloses a broken access control flaw (CVE-2026-17059) and provides a patch in version 26.7.0, detailing the vulnerability but not any exploit or ongoing attacks.

    0000043
    36 followersView on X
  • The Daily Tech Feed@dailytechonx
    Patch

    Keycloak has patched CVE-2026-17059, a vulnerability allowing restricted admins to access user data beyond their scope. Organizations should upgrade to version 26.7.0 to mitigate this security risk. #Keycloak #CVE202617059 #CyberSecurity #AccessControl #DataPrivacy #SecurityUpdate https://thedailytechfeed.com/keycloak-flaw-exposes-user-data-across-admin-boundaries/

    Post summary

    Keycloak has released a patch for CVE-2026-17059, advising users to upgrade to version 26.7.0 to mitigate the risk of unauthorized data access by restricted admins.

    0000057
    582 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appredhatbuild_of_keycloak---

Explore more