A broken access control vulnerability in Keycloak could allow unauthorized administrator accounts to access users’ personal information. This issue, tracked as CVE-2026-17059, affects the Keycloak Admin REST API and was discovered by researcher Enzo Mongin from Escape Research, also known as Orionexe. The vulnerability was reported to the Keycloak team on July 18, 2026, acknowledged […] The post Keycloak Flaw Exposes Users’ Personal Data to Restricted Admins appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
First seen on gbhackers.com
Jump to article: gbhackers.com/keycloak-flaw-exposes-users-personal-data/
![]()

