LOW3.1
GHSA-r8jr-wg88-fq5c
Keycloak vulnerable to authorization bypass via the Admin API
Details
A flaw was found in Keycloak. An authorization bypass vulnerability in the Keycloak Admin API allows any authenticated user, even those without administrative privileges, to enumerate the organization memberships of other users. This information disclosure occurs if the attacker knows the victim's unique identifier (UUID) and the Organizations feature is enabled.
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/@keycloak/keycloak-admin-client
Introduced in:
0No fixed version published yet for @keycloak/keycloak-admin-client (npm). Pin to a known-safe version or switch to an alternative.
Maven/org.keycloak:keycloak-js-admin-client
Introduced in:
0No fixed version published yet for org.keycloak:keycloak-js-admin-client (maven). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2026-2366[ADVISORY]
- https://github.com/keycloak/keycloak/issues/47062[WEB]
- https://access.redhat.com/errata/RHSA-2026:6477[WEB]
- https://access.redhat.com/errata/RHSA-2026:6478[WEB]
- https://access.redhat.com/security/cve/CVE-2026-2366[WEB]
- https://bugzilla.redhat.com/show_bug.cgi?id=2439081[WEB]
- https://github.com/keycloak/keycloak[PACKAGE]