在开源身份与访问管理解决方案 Keycloak 的授权服务(Authorization Services)组件中,发现存在一个漏洞。该问题出现在策略评估端点(policy evaluation endpoint)中,该端点由管理员用于测试访问策略如何应用于特定用户。由于缺乏适当的授权检查,拥有受限查看权限的委派管理员(delegated administrator)可以访问该领域(realm)中任意用户的完整个人资料和角色信息,即使他们本无权查看用户详细信息。这可能导致敏感信息泄露,例如电子邮件地址和已分配的安全角
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Build of Keycloak | - |
cpe:/a:redhat:build_keycloak:
|
|
| Red Hat | Red Hat Build of Keycloak | - |
cpe:/a:redhat:build_keycloak:
|
|
| Red Hat | Red Hat Build of Keycloak | - |
cpe:/a:redhat:build_keycloak:
|
|
| Red Hat | Red Hat Single Sign-On 7 | - |
cpe:/a:redhat:red_hat_single_sign_on:7
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-94215 | 5.5 MEDIUM | Keycloak-services: keycloak-services: cross-realm client read/write via request-level cach |
| CVE-2026-94217 | 3.5 LOW | Keycloak-services: keycloak-services: uma scope merge across resource owners via resource |
| CVE-2026-94218 | 3.1 LOW | Keycloak-services: keycloak-services: 2fa setup enforcement bypass via authentication sess |
No comments yet