CVE Vulnerabilities

CVE-2026-7500

Direct Request ('Forced Browsing')

Published: Apr 30, 2026 | Modified: Jun 26, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
5.4 MODERATE
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Ubuntu
root.io logo minimus.io logo echo.ai logo

When Keycloak is started with --features-disabled=account,account-api, the Account REST API is only partially disabled. Five endpoints under the versioned path /account/v1alpha1 remain fully functional — including both read and write operations — because they lack the checkAccountApiEnabled() gate that correctly blocks four other endpoints in the same REST service class. The user needs to have permissions to use the API.

Weakness

The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.

Affected Software

NameVendorStart VersionEnd Version
Build_of_keycloakRedhat- (including)- (including)
Red Hat build of Keycloak 26.4RedHatrhbk/keycloak-operator-bundle:26.4.13-1*
Red Hat build of Keycloak 26.4RedHatrhbk/keycloak-rhel9:26.4-19*
Red Hat build of Keycloak 26.4RedHatrhbk/keycloak-rhel9-operator:26.4-19*
Red Hat build of Keycloak 26.4.13RedHatrhbk/keycloak-rhel9*
Red Hat build of Keycloak 26.6RedHatrhbk/keycloak-operator-bundle:26.6.3-3*
Red Hat build of Keycloak 26.6RedHatrhbk/keycloak-rhel9:26.6-6*
Red Hat build of Keycloak 26.6RedHatrhbk/keycloak-rhel9-operator:26.6-6*
Red Hat build of Keycloak 26.6.3RedHatrhbk/keycloak-rhel9*

Potential Mitigations

References