A flaw was found in org.keycloak.services. An administrator with delegated access to read group memberships and users can bypass user profile permissions by accessing the group members endpoint. This allows the administrator to view user attributes that are explicitly configured to be denied, leading to information disclosure.
References
Configurations
No configuration.
History
26 Jun 2026, 08:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
10 Jun 2026, 22:17
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
10 Jun 2026, 18:17
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
05 Jun 2026, 08:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-05 08:16
Updated : 2026-06-26 08:16
NVD link : CVE-2026-9088
Mitre link : CVE-2026-9088
CVE.ORG link : CVE-2026-9088
JSON object : View
Products Affected
No product.
CWE
CWE-1220
Insufficient Granularity of Access Control
