Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Phase Two, Inc

Phase Two, Inc Vendor Cyber Rating & Cyber Score

phasetwo.io

Phase Two is a Keycloak Hosting and Support company that specializes in Enterprise Identity and Access Management (IAM) use-cases. Keycloak, an open-source IAM system, is a highly capable and complex tool that allows businesses of any size integrate a full-fledged IAM system. Teams that switch to Phase Two see 80% savings on their identity spend. Phase Two is one of the top community contributors through popular Keycloak extensions, bug reports and fixes, and forum maintainers. Phase Two helps companies with Keycloak in a variety ways: - First line Support for Keycloak installs at any scale - Upgrades in Keycloak versions, Cloud or On-Prem - Migration to Keycloak, multi-applications and IAM systems to Keycloak - Complex


PTI A.I CyberSecurity Scoring

PTI
Company Information
Website:https://phasetwo.io/
Employees number:1
Number of followers:20
NAICS:5112
Industry Type:Software Development
Homepage:phasetwo.io
PTI Risk Score (AI oriented)
Between 750 and 799
logo
PTISoftware Development
Updated:
31/07/2026
750/1000
Fair
Baa
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
PTI Global Score (TPRM)
xxxx
logo
PTISoftware Development
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

PTI
PTIFair
Current Score
750Baa (FAIR)
01000
1 incidents
-3 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
750Before Incident
JULY 2026
753Before Incident
Vulnerability
24 Jul 2026PTI
Keycloak: Keycloak Vulnerability Exposes User Names and Email Addresses Across Admin Boundaries

Keycloak Patches Broken Access Control Flaw Exposing User Data

750After Incident
CRITICAL-3
PHA1785522523
Keycloak Patches Broken Access Control Flaw Exposing User Data Keycloak has resolved a broken access control vulnerability (CVE-2026-17059) that allowed restricted administrators to access sensitive user data including usernames, email addresses, and profile details outside their authorized scope. The flaw, discovered by Escape researcher Enzo Mongin (Orionexe), affected the Keycloak Admin REST API and was disclosed by Red Hat on July 24, 2026. The issue stemmed from the `GET /admin/realms/{realm}/roles/{role-name}/users` endpoint, which failed to enforce proper per-user authorization checks. While Keycloak’s primary user-listing API correctly blocked restricted admins from viewing all users, the role-members endpoint only required `query-users` and `view-realm` permissions, allowing unauthorized access to full user records. The vulnerability, classified as CWE-639 (Broken Object-Level Authorization), carries a CVSS score of 6.5 (Medium). Exploitation required an authenticated but limited admin account, posing risks in environments where partial administrative access is delegated to support teams or business units. Keycloak addressed the flaw in version 26.7.0 (released July 28, 2026) by adding per-user visibility validation before returning records. The fix does not affect realms using fine-grained admin permissions (v2), where filtering occurs at the data-store layer. However, deployments with `adminPermissionsEnabled` set to false remain vulnerable. Organizations are advised to upgrade to Keycloak 26.7.0 or later and review accounts with `query-users` and `view-realm` roles, particularly in multi-team setups. Security teams should also audit related API endpoints to ensure consistent authorization enforcement.
INCIDENT DETAILS -
TYPE
Broken Access Control
IMPACT
Data Compromised: Usernames, email addresses, profile detailsSystems Affected: Keycloak Admin REST APIIdentity Theft Risk: High
DATA BREACH
Type Of Data Compromised: Personally Identifiable Information (PII)Sensitivity Of Data: HighPersonally Identifiable Information: Usernames, email addresses, profile details
JUNE 2026
753Before Incident
MAY 2026
753Before Incident
APRIL 2026
753Before Incident
MARCH 2026
753Before Incident
FEBRUARY 2026
753Before Incident
JANUARY 2026
753Before Incident
DECEMBER 2025
753Before Incident
NOVEMBER 2025
753Before Incident
OCTOBER 2025
753Before Incident
SEPTEMBER 2025
753Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for PTI ?
?
What was PTI's A.I Rankiteo Cyber Score in July 2026 ?
?
What was PTI's A.I Rankiteo Cyber Score in June 2026 ?
?
What was PTI's A.I Rankiteo Cyber Score in May 2026 ?
?
What was PTI's A.I Rankiteo Cyber Score in April 2026 ?
?
What was PTI's A.I Rankiteo Cyber Score in March 2026 ?
?
What was PTI's A.I Rankiteo Cyber Score in February 2026 ?
?
What was PTI's A.I Rankiteo Cyber Score in January 2026 ?
?
What was PTI's A.I Rankiteo Cyber Score in December 2025 ?
?
What was PTI's A.I Rankiteo Cyber Score in November 2025 ?
?
What was PTI's A.I Rankiteo Cyber Score in October 2025 ?
?
What was PTI's A.I Rankiteo Cyber Score in September 2025 ?
?
What is the average per-incident point impact on PTI's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with PTI ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view PTI's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?