CVE-2026-37981
Keycloak Account Resources user lookup contains broken access control
4.3
MEDIUM
CVSS 3.1
EPSS 0.37%
Description
Keycloak's Account Resources user lookup endpoint allows a remote authenticated user, who owns at least one User-Managed Access (UMA) resource, to enumerate and harvest personally identifiable information (PII) for all realm users. By sending crafted requests with arbitrary usernames or email values, the endpoint returns full profile objects for unrelated users. This leads to broad profile-level information disclosure.
How to fix CVE-2026-37981
To remediate CVE-2026-37981, upgrade the affected package to a fixed version below.
- —upgrade to 26.4.12 or later
Is CVE-2026-37981 being exploited?
Low — EPSS is 0.4%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 26.4.12
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM4.3 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |