Skip to main content
Loading…
    CVE-2026-37978 — A flaw was found in Keycloak. A low-privilege administrator with the 'view-clients' role can exploit this by invoking the 'evaluate-scopes' Admin API endpoints with an arbitrary user ID (userId) param — CVE Database · The Intelligence Room