Skip to content
Keycloak Vulnerabilities CVE-2026-94213 and CVE-2026-94217 Disclosed

Keycloak Vulnerabilities CVE-2026-94213 and CVE-2026-94217 Disclosed

First seen 21 Sep 2026, 17:53 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 21, 2026 at 18:54 UTC
  • CVE-2026-94213 allows unauthorized access to user profiles by privileged accounts.
  • CVE-2026-94217 merges permissions incorrectly, potentially exposing user resources.
  • Immediate patching is advised for both vulnerabilities to mitigate risks.

Two vulnerabilities in Keycloak, an open-source identity and access management solution, were disclosed on September 21, 2026. CVE-2026-94213 is a medium-severity flaw in the Authorization Services component, allowing delegated administrators to access sensitive user information due to missing authorization checks. This vulnerability requires high-privilege access and can be exploited remotely without user interaction. CVE-2026-94217 is a low-severity issue in the User-Managed Access implementation, where incorrect merging of permissions can lead to unauthorized access to resources. This flaw requires low-privilege access and user interaction to exploit. Both vulnerabilities have been published and patches are recommended for immediate application.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Timeline

2026-09-21
CVE-2026-94213 published
A medium-severity flaw in Keycloak's Authorization Services allows unauthorized access to user profiles.
Ervik.As
2026-09-21
CVE-2026-94217 published
A low-severity flaw in Keycloak's User-Managed Access implementation allows permission merging issues.
Ervik.As

More articles in this cluster (4)

Following this threat?

Track CVE-2026-94213 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed