A flaw was found in Keycloak. A broken access control vulnerability in the Account Resources user lookup endpoint allows a remote authenticated user, who owns at least one User-Managed Access (UMA) resource, to enumerate and harvest personally identifiable information (PII) for all realm users. By sending crafted requests with arbitrary usernames or email values, the endpoint returns full profile objects for unrelated users. This leads to broad profile-level information disclosure.
History

Wed, 20 May 2026 16:45:00 +0000

Type Values Removed Values Added
References

Wed, 20 May 2026 12:15:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:build_keycloak: cpe:/a:redhat:build_keycloak:26.4::el9
References

Wed, 20 May 2026 11:45:00 +0000

Type Values Removed Values Added
First Time appeared Redhat build Of Keycloak
Vendors & Products Redhat build Of Keycloak

Tue, 19 May 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 19 May 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Tue, 19 May 2026 11:30:00 +0000

Type Values Removed Values Added
Description A flaw was found in Keycloak. A broken access control vulnerability in the Account Resources user lookup endpoint allows a remote authenticated user, who owns at least one User-Managed Access (UMA) resource, to enumerate and harvest personally identifiable information (PII) for all realm users. By sending crafted requests with arbitrary usernames or email values, the endpoint returns full profile objects for unrelated users. This leads to broad profile-level information disclosure.
Title Keycloak: org.keycloak.authorization: keycloak: information disclosure via broken access control in user lookup endpoint
First Time appeared Redhat
Redhat build Keycloak
Weaknesses CWE-1220
CPEs cpe:/a:redhat:build_keycloak:
Vendors & Products Redhat
Redhat build Keycloak
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2026-05-19T10:28:24.207Z

Updated: 2026-05-20T16:08:56.545Z

Reserved: 2026-04-06T07:48:39.722Z

Link: CVE-2026-37981

cve-icon Vulnrichment

Updated: 2026-05-19T12:06:10.279Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-05-19T12:16:18.463

Modified: 2026-05-20T17:16:21.960

Link: CVE-2026-37981

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-05-19T10:19:46Z

Links: CVE-2026-37981 - Bugzilla