CVE-2026-9088 — A flaw was found in org.keycloak.services. An administrator with delegated access to read group memberships and users can bypass user profile permissions by accessing the group members endpoint. This — CVE Database · The Intelligence Room