CVE Record
[ MEDIUM ]CVE-2026-94213
Keycloak authorization policy evaluation exposes permissions
A flaw in the Keycloak Authorization Services policy evaluation endpoint can surface permission information beyond what is intended. Red Hat rates this CVSS 4.9 medium.
- Vendor
- Red Hat
- Product
- Keycloak
- CVSS
- 4.9
- EPSS (exploit probability)
- N/A
- Status
- patched
- Published
The Authorization Services component in Keycloak exposes a policy evaluation endpoint used by administrators to test authorization policies. A flaw in the endpoint can surface permission information beyond what is intended.
Red Hat rates this CVSS 4.9 (medium). No active exploitation reported. Patched versions are listed in the Red Hat advisory.
