Report: CVE-2026-7500 - Org.keycloak.keycloak-services: improper access control on keycloak server when t
CVE ID :CVE-2026-7500 Published : April 30, 2026, 2:53 p.m. | 21 minutes ago Description :When Keycloak is started with `--features-disabled=account,account-api`, the Account REST API is only partially disabled. Five endpoints under the versioned path `/account/v1alpha1` remain fully functional — including both read and write operations — because they lack the `checkAccountApiEnabled()` gate that correctly blocks four other endpoints in the same REST service class. The user needs to have permissions to use the API. Severity: 5.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...