
Keycloak Flaw Exposes User PII Through Malicious OIDC Client Metadata
A newly disclosed broken access control vulnerability in Keycloak, the widely deployed open-source identity and access management server that underpins the Red Hat build. Tracked as CVE-2026-17059, the flaw allows a deliberately restricted admin account to harvest the personal data of users it should never be able to view by querying a role’s membership rather […]
The post Keycloak Flaw Exposes User PII Through Malicious OIDC Client Metadata appeared first on Cyber Security News.