LIVE · cybersecurity feed
Live wire
cve recordlow

CVE-2026-2366

redhat · build of keycloak

Published
CVSS3.1
Severitylow
WeaknessCWE-639
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N

Description

A flaw was found in Keycloak. An authorization bypass vulnerability in the Keycloak Admin API allows any authenticated user, even those without administrative privileges, to enumerate the organization memberships of other users. This information disclosure occurs if the attacker knows the victim's unique identifier (UUID) and the Organizations feature is enabled.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-2366

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-2366.