{"id":"CVE-2019-14832","aliases":["GHSA-8prc-58j4-m55q"],"url":"https://o3.security/vulnerability/CVE-2019-14832","summary":"Keycloak Unauthenticated Access","details":"A flaw was found in the Keycloak REST API before version 8.0.0, implemented in Keycloak before 7.0.1 where it would permit user access from a realm the user was not configured. An authenticated attacker with knowledge of a user id could use this flaw to access unauthorized information or to carry out further attacks.","published":"2019-10-15T19:15:11.927Z","modified":"2026-08-07T15:18:01.510193Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.keycloak:keycloak-model-infinispan","fixedVersion":"7.0.1"},{"ecosystem":"Maven","name":"org.keycloak:keycloak-model-jpa","fixedVersion":"7.0.1"}],"fix":{"url":"https://github.com/keycloak/keycloak/commit/0b73685ccf3181115ae3936a578708630215ac23","label":"keycloak/keycloak@0b73685"},"references":[{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14832"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-14832"},{"type":"WEB","url":"https://github.com/keycloak/keycloak/commit/0b73685ccf3181115ae3936a578708630215ac23"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T15:18:01.510193Z"}}