PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-94213 Red Hat CVE debrief

A flaw in Keycloak's Authorization Services component allows a delegated administrator with limited viewing privileges to access the full profile and role information of any user in the realm. This could expose sensitive information such as email addresses and assigned security roles. The issue arises from missing authorization checks in the policy evaluation endpoint used by administrators to test access policies. This vulnerability may lead to unauthorized exposure of sensitive user information, emphasizing the need for administrators to verify and limit access controls.

Vendor
Red Hat
Product
Red Hat Build of Keycloak
CVSS
MEDIUM 4.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-21
Original CVE updated
2026-09-21
Advisory published
2026-09-21
Advisory updated
2026-09-21

Who should care

Administrators and security teams responsible for Keycloak deployments should assess exposure and verify administrator access controls. They should review the vulnerability's impact on user privacy and security, and ensure that appropriate measures are taken to limit unauthorized access to sensitive user information. Security teams should also monitor for potential misuse of administrator privileges and review access policies for administrators.

Why it matters

A flaw in Keycloak's Authorization Services component allows unauthorized access to sensitive user information, potentially impacting user privacy and security.

  • Potential exposure of sensitive user information
  • Possible misuse of administrator privileges
  • Need for verification and limitation of administrator access
  • Potential impact on user privacy and security

Technical summary

The policy evaluation endpoint in Keycloak's Authorization Services component is vulnerable to unauthorized access. This allows a delegated administrator with limited viewing privileges to access the full profile and role information of any user in the realm. The vulnerability stems from missing authorization checks, potentially exposing sensitive information such as email addresses and assigned security roles. Technical impact includes unauthorized data access and potential misuse of administrator privileges. Defenders should prioritize verifying and limiting administrator access to sensitive user information.

Defensive priority

Defenders should prioritize verifying and limiting administrator access to sensitive user information.

Recommended defensive actions

  • Verify and limit administrator access to sensitive user information
  • Review and update access policies for administrators
  • Monitor for potential misuse of administrator privileges
  • Confirm whether affected Keycloak deployments exist in managed environments
  • Review compensating controls for exposed systems while remediation is scheduled
  • Check relevant monitoring, detection, and logs for exposed assets
  • Track exceptions and retest remediated assets

Evidence notes

The CVE record and NVD entry provide details on the flaw in Keycloak's Authorization Services component. Evidence is based on official CVE metadata and NVD vulnerability assessment. The issue is confirmed in Keycloak's policy evaluation endpoint, allowing unauthorized access to user profiles and roles. Defenders should verify administrator access controls and review user information exposure.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-94213 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-94213

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-94213 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-94213

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.