CVE-2026-2366
An authorization bypass vulnerability in the Keycloak Admin API allows any authenticated user, even those without administrative privileges, to enumerate the organization memberships of other users.
Does this matter?
Lower severity and a low EPSS score (0.27%). Track it; it rarely justifies an emergency change on its own.
Description
A flaw was found in Keycloak. An authorization bypass vulnerability in the Keycloak Admin API allows any authenticated user, even those without administrative privileges, to enumerate the organization memberships of other users. This information disclosure occurs if the attacker knows the victim's unique identifier (UUID) and the Organizations feature is enabled.
- CVSS 3.1
- 3.1 LOWCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 0.27% probability · 19th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-639
- Affected
- redhat/build of keycloak
- Source
- secalert@redhat.com
References
- https://access.redhat.com/errata/RHSA-2026:6477Vendor Advisory
- https://access.redhat.com/errata/RHSA-2026:6478Vendor Advisory
- https://access.redhat.com/security/cve/CVE-2026-2366Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2439081Exploit, Issue Tracking, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.