PTI A.I CyberSecurity Scoring
PTI
Company Information
Website:https://phasetwo.io/
Employees number:1
Number of followers:20
NAICS:5112
Industry Type:Software Development
Homepage:phasetwo.io
PTI Risk Score (AI oriented)
Between 750 and 799
PTISoftware Development
Updated:
31/07/2026
31/07/2026
750/1000
Fair
Baa
PTI Global Score (TPRM)
xxxx
PTISoftware Development
Score locked

PTIFair
Current Score
750Baa (FAIR)
01000
1 incidents
-3 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
750
JULY 2026
753
Vulnerability
24 Jul 2026 • PTI
Keycloak: Keycloak Vulnerability Exposes User Names and Email Addresses Across Admin Boundaries
Keycloak Patches Broken Access Control Flaw Exposing User Data
750
CRITICAL-3
PHA1785522523
Keycloak Patches Broken Access Control Flaw Exposing User Data
Keycloak has resolved a broken access control vulnerability (CVE-2026-17059) that allowed restricted administrators to access sensitive user data including usernames, email addresses, and profile details outside their authorized scope. The flaw, discovered by Escape researcher Enzo Mongin (Orionexe), affected the Keycloak Admin REST API and was disclosed by Red Hat on July 24, 2026.
The issue stemmed from the `GET /admin/realms/{realm}/roles/{role-name}/users` endpoint, which failed to enforce proper per-user authorization checks. While Keycloak’s primary user-listing API correctly blocked restricted admins from viewing all users, the role-members endpoint only required `query-users` and `view-realm` permissions, allowing unauthorized access to full user records.
The vulnerability, classified as CWE-639 (Broken Object-Level Authorization), carries a CVSS score of 6.5 (Medium). Exploitation required an authenticated but limited admin account, posing risks in environments where partial administrative access is delegated to support teams or business units.
Keycloak addressed the flaw in version 26.7.0 (released July 28, 2026) by adding per-user visibility validation before returning records. The fix does not affect realms using fine-grained admin permissions (v2), where filtering occurs at the data-store layer. However, deployments with `adminPermissionsEnabled` set to false remain vulnerable.
Organizations are advised to upgrade to Keycloak 26.7.0 or later and review accounts with `query-users` and `view-realm` roles, particularly in multi-team setups. Security teams should also audit related API endpoints to ensure consistent authorization enforcement.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
JUNE 2026
753
MAY 2026
753
APRIL 2026
753
MARCH 2026
753
FEBRUARY 2026
753
JANUARY 2026
753
DECEMBER 2025
753
NOVEMBER 2025
753
OCTOBER 2025
753
SEPTEMBER 2025
753
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for PTI ??
What was PTI's A.I Rankiteo Cyber Score in July 2026 ??
What was PTI's A.I Rankiteo Cyber Score in June 2026 ??
What was PTI's A.I Rankiteo Cyber Score in May 2026 ??
What was PTI's A.I Rankiteo Cyber Score in April 2026 ??
What was PTI's A.I Rankiteo Cyber Score in March 2026 ??
What was PTI's A.I Rankiteo Cyber Score in February 2026 ??
What was PTI's A.I Rankiteo Cyber Score in January 2026 ??
What was PTI's A.I Rankiteo Cyber Score in December 2025 ??
What was PTI's A.I Rankiteo Cyber Score in November 2025 ??
What was PTI's A.I Rankiteo Cyber Score in October 2025 ??
What was PTI's A.I Rankiteo Cyber Score in September 2025 ??
What is the average per-incident point impact on PTI's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with PTI ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view PTI's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?