When Keycloak is started with `--features-disabled=account,account-api`, the Account REST API is only partially disabled. Five endpoints under the versioned path `/account/v1alpha1` remain fully functional — including both read and write operations — because they lack the `checkAccountApiEnabled()` gate that correctly blocks four other endpoints in the same REST service class. The user needs to have permissions to use the API.
Metrics
Affected Vendors & Products
References
History
Thu, 30 Apr 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat build Of Keycloak
|
|
| Vendors & Products |
Redhat build Of Keycloak
|
Thu, 30 Apr 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 30 Apr 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | When Keycloak is started with `--features-disabled=account,account-api`, the Account REST API is only partially disabled. Five endpoints under the versioned path `/account/v1alpha1` remain fully functional — including both read and write operations — because they lack the `checkAccountApiEnabled()` gate that correctly blocks four other endpoints in the same REST service class. The user needs to have permissions to use the API. | |
| Title | Org.keycloak.keycloak-services: improper access control on keycloak server when the account account api feature is disabled | |
| First Time appeared |
Redhat
Redhat build Keycloak |
|
| Weaknesses | CWE-425 | |
| CPEs | cpe:/a:redhat:build_keycloak: | |
| Vendors & Products |
Redhat
Redhat build Keycloak |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-04-30T15:10:45.325Z
Reserved: 2026-04-30T14:32:50.005Z
Link: CVE-2026-7500
Updated: 2026-04-30T15:06:53.790Z
Status : Awaiting Analysis
Published: 2026-04-30T15:16:23.673
Modified: 2026-04-30T15:48:26.580
Link: CVE-2026-7500
No data.
OpenCVE Enrichment
Updated: 2026-04-30T16:30:15Z