Red HatCVE-2026-17059
Red Hat role-users endpoint: insecure direct object reference
Medium6.5CVE-2026-17059 · Published Jul 24, 2026 · updated Sep 16, 2026
A flaw was found in the role-users endpoint of the keycloak-services library, which is the core component of the Keycloak identity and access management solution. The issue occurs because the system fails to check if an administrator has permission to view individual users when listing members of a role. This allows a restricted administrator to see private information, such as names and email addresses, for users they should not be able to access.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Red Hat Data Grid 8 Product | all versions | No fix yet |
| Red Hat JBoss Enterprise Application Platform Expansion Pack Product | all versions | No fix yet |
| Red Hat Single Sign-On 7 Product | all versions | No fix yet |
| Red Hat build of Keycloak 26.6.7 Product | all versions | No fix yet |
| all versions | No fix yet | |
| all versions | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-639
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 24 | Red Hat libsoup: request smuggling | Medium5.4 | No fix yet |
| Jul 24 | Red Hat libsoup: information disclosure | Medium6.5 | No fix yet |
| Jul 24 | Red Hat libsoup. An unsigned integer underflow: integer overflow | Medium6.5 | No fix yet |
| Jul 24 | A flaw was found in the cluster-proxy service-proxy component used in Red Hat... | High8.5 | No fix yet |
| Jul 24 | Red Hat pki-core: improper authorization | Low3.1 | No fix yet |
| Jul 24 | Red Hat Keycloak Admin REST API: information disclosure | Medium5.5 | No fix yet |