CVE-2026-7500: Red Hat Build Of Keycloak
Medium severity, CVSS 5.4. EPSS: 0.3% chance of exploitation in the next 30 days.
When Keycloak is started with `--features-disabled=account,account-api`, the Account REST API is only partially disabled. Five endpoints under the versioned path `/account/v1alpha1` remain fully functional — including both read and write operations — because they lack the `checkAccountApiEnabled()` gate that correctly blocks four other endpoints in the same REST service class. The user needs to have permissions to use the API.
Affected products
- Red Hat Build Of Keycloak: affected versions not specified
Published 2026-04-30. Last modified 2026-06-26.