CVE detail
CVE-2026-37981
A flaw was found in Keycloak. A broken access control vulnerability in the Account Resources user lookup endpoint allows a remote authenticated user, who owns at least one User-Managed Access (UMA) resource, to enumerate and harvest personally identifiable information (PII) for all realm users. By sending crafted requests with arbitrary usernames or email values, the endpoint returns full profile objects for unrelated users. This leads to broad profile-level information disclosure.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 16.1 · diversity 10.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
4 source links · newest first
- https://bugzilla.redhat.com/show_bug.cgi?id=2455326bugzilla.redhat.com
No excerpt available.
Exploitbugzilla.redhat.comMay 19, 2026, 12:16 PM - https://access.redhat.com/security/cve/CVE-2026-37981access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 19, 2026, 12:16 PM - https://access.redhat.com/errata/RHSA-2026:19597access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 19, 2026, 12:16 PM - https://access.redhat.com/errata/RHSA-2026:19596access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 19, 2026, 12:16 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-16560CVSS 5.3 · Medium
A heap-buffer-overflow flaw was found in Directory Server (389-ds-base). When a DN contains a legacy-quoted value, the server won't close the heap allocation allowing another call…
- CVE-2026-50502CVSS 8.0 · High
Insufficient granularity of access control in Windows Event Logging Service allows an authorized attacker to execute code over a network.
- CVE-2026-50405CVSS 7.8 · High
Insufficient granularity of access control in Windows Filtering Platform (WFP) allows an authorized attacker to elevate privileges locally.
- CVE-2026-56155CVSS 7.8 · High
Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.
- CVE-2026-55006CVSS 7.8 · High
Insufficient granularity of access control in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally.
- CVE-2026-49170CVSS 7.8 · High
Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to elevate privileges locally.