CVE-2026-7500Medium· 5.4▾ SunlitWhen Keycloak is started with `--features-disabled=account,account-api`, the Account REST API is only partially disabled. Five endpoints under the versioned path `/account/v1alpha1` remain fully functional — including both read and write…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
When Keycloak is started with --features-disabled=account,account-api, the Account REST API is only partially disabled. Five endpoints under the versioned path /account/v1alpha1 remain fully functional — including both read and write operations — because they lack the checkAccountApiEnabled() gate that correctly blocks four other endpoints in the same REST service class. The user needs to have permissions to use the API.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-40532Medium· 6.5A direct request ('forced browsing') vulnerability in Wallpaper Path in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to obtain sensitive information.
CVE-2026-36453High· 7.4Rhymix before 2.1.31 allows insecure direct object reference, aka RVE-2026-1
CVE-2026-19903Medium· 5.3A vulnerability has been found in SourceCodester Online Clothing Store 1.0
CVE-2026-11986Medium· 4.9A flaw was found in the admin-ui-ext component of Keycloak, which provides extended administrative user interface capabilities
CVE-2026-33217High· 7.1NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system
CVE-2026-0650NoneOpenFlagr versions prior to and including 1.1.18 contain an authentication bypass vulnerability in the HTTP middleware