CVE-2026-37978: Red Hat Build Of Keycloak
Medium severity, CVSS 4.9. EPSS: 0.5% chance of exploitation in the next 30 days.
A flaw was found in Keycloak. A low-privilege administrator with the 'view-clients' role can exploit this by invoking the 'evaluate-scopes' Admin API endpoints with an arbitrary user ID (userId) parameter. This vulnerability allows for cross-role personally identifiable information (PII) leakage, enabling unauthorized visibility into user identities and authorizations across the realm. Exploitation is possible remotely via network access to the Admin API.
Affected products
- Red Hat Build Of Keycloak: before 26.4.12 (fixed in 26.4.12)
Published 2026-05-19. Last modified 2026-06-17.