Home

Description

When Keycloak is started with `--features-disabled=account,account-api`, the Account REST API is only partially disabled. Five endpoints under the versioned path `/account/v1alpha1` remain fully functional — including both read and write operations — because they lack the `checkAccountApiEnabled()` gate that correctly blocks four other endpoints in the same REST service class. The user needs to have permissions to use the API.

PUBLISHED Reserved 2026-04-30 | Published 2026-04-30 | Updated 2026-04-30 | Assigner redhat




MEDIUM: 5.4CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

Problem types

Direct Request ('Forced Browsing')

Product status

Default status
affected

Timeline

2026-04-30:Reported to Red Hat.
2026-04-30:Made public.

Credits

Red Hat would like to thank Evan Hendra for reporting this issue.

References

access.redhat.com/security/cve/CVE-2026-7500 vdb-entry

bugzilla.redhat.com/show_bug.cgi?id=2464126 (RHBZ#2464126) issue-tracking

cve.org (CVE-2026-7500)

nvd.nist.gov (CVE-2026-7500)

Download JSON