CVE-2026-7500
ADVISORY - githubSummary
When Keycloak is started with --features-disabled=account,account-api, the Account REST API is only partially disabled. Five endpoints under the versioned path /account/v1alpha1 remain fully functional — including both read and write operations — because they lack the checkAccountApiEnabled() gate that correctly blocks four other endpoints in the same REST service class. The user needs to have permissions to use the API.
EPSS Score: 0.00026 (0.073)
Common Weakness Enumeration (CWE)
ADVISORY - nist
Direct Request ('Forced Browsing')
ADVISORY - github
Direct Request ('Forced Browsing')
ADVISORY - redhat
Direct Request ('Forced Browsing')
NIST
CREATED
UPDATED
ADVISORY IDCVE-2026-7500
EXPLOITABILITY SCORE
2.8
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)
CVSS SCORE
5.4mediumGitHub
CREATED
UPDATED
ADVISORY IDGHSA-hm32-hfmw-rhvg
EXPLOITABILITY SCORE
2.8
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)
CVSS SCORE
5.4mediumRed Hat
CREATED
UPDATED
ADVISORY IDCVE-2026-7500
EXPLOITABILITY SCORE
2.8
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)
CVSS SCORE
5.4mediumChainguard
CREATED
UPDATED
ADVISORY ID
CGA-q8rh-w844-w94h
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
minimos
CREATED
UPDATED
ADVISORY ID
MINI-4wph-75wx-fjpq
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
minimos
CREATED
UPDATED
ADVISORY ID
MINI-8rg5-9gr6-p585
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-