What is CVE-2026-17059?
A vulnerability exists in the `role-users` endpoint of Keycloak's core library where permission checks fail to verify an administrator's access to view individual users when listing role members. It is recommended to update Keycloak to the latest patched version to mitigate this issue.
Azərbaycanca: Keycloak identifikasiya həllində `role-users` endpoint-də icazə yoxlanışı qüsuru aşkar edilib. Administrator rolun üzvlərini siyahıya alarkən fərdi istifadəçilərə baxma icazəsini düzgün yoxlanmır. Təsirə məruz qalmamaq üçün Keycloak-ı ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
In which Keycloak endpoint was the permission check flaw discovered?
The flaw was discovered in the `role-users` endpoint.
What is recommended to mitigate CVE-2026-17059?
It is recommended to update Keycloak to the latest patched version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.