Skip to content
feed: live
>_0dayNews
CVE Record
[ MEDIUM ]CVE-2026-94213

Keycloak authorization policy evaluation exposes permissions

A flaw in the Keycloak Authorization Services policy evaluation endpoint can surface permission information beyond what is intended. Red Hat rates this CVSS 4.9 medium.

cat cve-2026-94213.json
Vendor
Red Hat
Product
Keycloak
CVSS
4.9
EPSS (exploit probability)
N/A
Status
patched
Published

The Authorization Services component in Keycloak exposes a policy evaluation endpoint used by administrators to test authorization policies. A flaw in the endpoint can surface permission information beyond what is intended.

Red Hat rates this CVSS 4.9 (medium). No active exploitation reported. Patched versions are listed in the Red Hat advisory.