Skip to content

[26.4][CVE-2026-7500] Improper Access Control on Keycloak Server#48801

Open
mabartos wants to merge 1 commit intokeycloak:release/26.4from
mabartos:backport-48715-26.4
Open

[26.4][CVE-2026-7500] Improper Access Control on Keycloak Server#48801
mabartos wants to merge 1 commit intokeycloak:release/26.4from
mabartos:backport-48715-26.4

Conversation

@mabartos
Copy link
Copy Markdown
Member

@mabartos mabartos commented May 7, 2026

…ccount Account API feature is disabled

Closes keycloak#48709

Signed-off-by: Martin Bartoš <mabartos@redhat.com>
(cherry picked from commit 8e808ca)
@mabartos
Copy link
Copy Markdown
Member Author

mabartos commented May 7, 2026

@vramik Could you check this backport, please? Thanks!

@mabartos mabartos requested a review from vramik May 7, 2026 14:58
@mabartos mabartos self-assigned this May 7, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[CVE-2026-7500] Improper Access Control on Keycloak Server when the account Account API feature is disabled

1 participant