PatchSiren cyber security CVE debrief
CVE-2026-94213 Red Hat CVE debrief
A flaw in Keycloak's Authorization Services component allows a delegated administrator with limited viewing privileges to access the full profile and role information of any user in the realm. This could expose sensitive information such as email addresses and assigned security roles. The issue arises from missing authorization checks in the policy evaluation endpoint used by administrators to test access policies. This vulnerability may lead to unauthorized exposure of sensitive user information, emphasizing the need for administrators to verify and limit access controls.
- Vendor
- Red Hat
- Product
- Red Hat Build of Keycloak
- CVSS
- MEDIUM 4.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-21
- Original CVE updated
- 2026-09-21
- Advisory published
- 2026-09-21
- Advisory updated
- 2026-09-21
Who should care
Administrators and security teams responsible for Keycloak deployments should assess exposure and verify administrator access controls. They should review the vulnerability's impact on user privacy and security, and ensure that appropriate measures are taken to limit unauthorized access to sensitive user information. Security teams should also monitor for potential misuse of administrator privileges and review access policies for administrators.
Why it matters
A flaw in Keycloak's Authorization Services component allows unauthorized access to sensitive user information, potentially impacting user privacy and security.
- Potential exposure of sensitive user information
- Possible misuse of administrator privileges
- Need for verification and limitation of administrator access
- Potential impact on user privacy and security
Technical summary
The policy evaluation endpoint in Keycloak's Authorization Services component is vulnerable to unauthorized access. This allows a delegated administrator with limited viewing privileges to access the full profile and role information of any user in the realm. The vulnerability stems from missing authorization checks, potentially exposing sensitive information such as email addresses and assigned security roles. Technical impact includes unauthorized data access and potential misuse of administrator privileges. Defenders should prioritize verifying and limiting administrator access to sensitive user information.
Defensive priority
Defenders should prioritize verifying and limiting administrator access to sensitive user information.
Recommended defensive actions
- Verify and limit administrator access to sensitive user information
- Review and update access policies for administrators
- Monitor for potential misuse of administrator privileges
- Confirm whether affected Keycloak deployments exist in managed environments
- Review compensating controls for exposed systems while remediation is scheduled
- Check relevant monitoring, detection, and logs for exposed assets
- Track exceptions and retest remediated assets
Evidence notes
The CVE record and NVD entry provide details on the flaw in Keycloak's Authorization Services component. Evidence is based on official CVE metadata and NVD vulnerability assessment. The issue is confirmed in Keycloak's policy evaluation endpoint, allowing unauthorized access to user profiles and roles. Defenders should verify administrator access controls and review user information exposure.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-94213 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-94213
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-94213 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-94213
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/security/cve/CVE-2026-94213
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.