Keycloak filters its main users list so a restricted admin sees nothing. The endpoint that lists a role’s members skips that filter and hands the same account everyone’s email and name. Escape research found it, reported it, and it’s now tracked as CVE-2026-17059.