PT-2026-36114 · Red Hat · Red Hat Build Of Keycloak

Published

2026-04-30

·

Updated

2026-04-30

·

CVE-2026-7500

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
When Keycloak is started with --features-disabled=account,account-api, the Account REST API is only partially disabled. Five endpoints under the versioned path /account/v1alpha1 remain fully functional — including both read and write operations — because they lack the checkAccountApiEnabled() gate that correctly blocks four other endpoints in the same REST service class. The user needs to have permissions to use the API.

Fix

Weakness Enumeration

Related Identifiers

CVE-2026-7500

Affected Products

Red Hat Build Of Keycloak