{"id":"CVE-2026-37978","aliases":["GHSA-rrv7-3mqf-hxfr"],"url":"https://o3.security/vulnerability/CVE-2026-37978","summary":"Keycloak: org.keycloak.services: keycloak: information disclosure via evaluate-scopes admin api","details":"A flaw was found in Keycloak. A low-privilege administrator with the 'view-clients' role can exploit this by invoking the 'evaluate-scopes' Admin API endpoints with an arbitrary user ID (userId) parameter. This vulnerability allows for cross-role personally identifiable information (PII) leakage, enabling unauthorized visibility into user identities and authorizations across the realm. Exploitation is possible remotely via network access to the Admin API.","published":"2026-08-25T11:42:18.839Z","modified":"2026-09-08T08:48:06.813998770Z","cvss":null,"epss":{"score":0.00398,"percentile":0.33017,"asOf":"2026-08-16"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Bitnami","name":"keycloak","fixedVersion":"26.4.12"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:19596"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:19597"},{"type":"ADVISORY","url":"https://access.redhat.com/security/cve/CVE-2026-37978"},{"type":"ADVISORY","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2455327"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-37978"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-08T08:48:06.813998770Z"}}