---
id: CVE-2026-94213
title: >-
  A flaw was found in the Authorization Services component of Keycloak, an
  open-source identity and access management solution
summary: >-
  A flaw was found in the Authorization Services component of Keycloak, an
  open-source identity and access management solution. The issue occurs in the
  policy evaluation endpoint, which is used by administrators to test how access
  policies…
severity: medium
cvss: 4.9
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-862
vendor: Red Hat
product: keycloak/rhbk-openshift-rhel9
affected:
  - keycloak/rhbk-openshift-rhel9 (all versions)
  - keycloak-services (all versions)
  - rhbk/keycloak-rhel9 (all versions)
  - keycloak-services
published: '2026-09-21'
updated: '2026-09-22'
sourceUpdated: '2026-09-22T19:37:36.747'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-94213'
references:
  - url: 'https://access.redhat.com/security/cve/CVE-2026-94213'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2537310'
    label: secalert@redhat.com
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-94213.json
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-94213'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-94213'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
epss: 0.00391
epssPercentile: 0.30535
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-21T15:36:51.344448Z'
ingestedAt: '2026-09-21T06:32:37.148Z'
---

## Overview

A flaw was found in the Authorization Services component of Keycloak, an open-source identity and access management solution. The issue occurs in the policy evaluation endpoint, which is used by administrators to test how access policies apply to specific users. Due to missing authorization checks, a delegated administrator with limited viewing privileges can access the full profile and role information of any user in the realm, even if they are not permitted to view user details. This could lead to the exposure of sensitive information such as email addresses and assigned security roles.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **Red Hat VEX** · Moderate · affected: Red Hat Build of Keycloak · no fix planned: Red Hat Build of Keycloak · updated 2026-09-25 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-94213.json)
