CVE-2026-37981
Keycloak Account Resources user lookup contains broken access control
4.3
MEDIUM
CVSS 3.1
EPSS 0.37%
描述
Keycloak's Account Resources user lookup endpoint allows a remote authenticated user, who owns at least one User-Managed Access (UMA) resource, to enumerate and harvest personally identifiable information (PII) for all realm users. By sending crafted requests with arbitrary usernames or email values, the endpoint returns full profile objects for unrelated users. This leads to broad profile-level information disclosure.
如何修補 CVE-2026-37981
要修補 CVE-2026-37981,請將受影響套件升級到下列已修補版本。
- —升級至 26.4.12 或更新版本
CVE-2026-37981 正在被利用嗎?
低 — EPSS 為 0.4%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- from 0, < 26.4.12
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM4.3 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |