{"id":"CVE-2025-1391","title":"A flaw was found in the Keycloak organization feature, which allows the incorrect assignment of an organization to a user if their username or email matches the organization’s domain pattern","summary":"A flaw was found in the Keycloak organization feature, which allows the incorrect assignment of an organization to a user if their username or email matches the organization’s domain pattern. This issue occurs at the mapper level, leadin…","severity":"medium","cvss":5.4,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","cwe":["CWE-284"],"vendor":"Red Hat","product":"keycloak-services","affected":["keycloak-services >= 26.0.0 < 26.0.10","keycloak-services","rhbk/keycloak-operator-bundle (all versions)","rhbk/keycloak-rhel9 (all versions)","rhbk/keycloak-rhel9-operator (all versions)"],"published":"2025-02-17","updated":"2026-09-21","sourceUpdated":"2026-09-21T06:17:00.010","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-1391","references":[{"url":"https://access.redhat.com/errata/RHSA-2025:2544","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:2545","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/security/cve/CVE-2025-1391","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2346082","label":"secalert@redhat.com"},{"url":"https://github.com/keycloak/keycloak/issues/37169","label":"secalert@redhat.com"},{"url":"https://github.com/keycloak/keycloak/pull/37235","label":"secalert@redhat.com"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-1391.json"},{"url":"https://www.cve.org/CVERecord?id=CVE-2025-1391"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-1391"}],"tags":["nvd","cve.org","csaf","vex","red-hat"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2025-02-18T17:17:45.272663Z"},"epss":0.0041,"epssPercentile":0.34856,"ingestedAt":"2026-09-21T06:32:37.141Z","patched":["build_of_keycloak 26.0","build_of_keycloak"],"slug":"CVE-2025-1391","body":"## Overview\n\nA flaw was found in the Keycloak organization feature, which allows the incorrect assignment of an organization to a user if their username or email matches the organization’s domain pattern. This issue occurs at the mapper level, leading to misrepresentation in tokens. If an application relies on these claims for authorization, it may incorrectly assume a user belongs to an organization they are not a member of, potentially granting unauthorized access or privileges.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Vendor advisories\n\n- **RHSA-2025:2544** · Red Hat · fixed in: Red Hat build of Keycloak 26.0 · released 2025-03-10 · [advisory](https://access.redhat.com/errata/RHSA-2025:2544)\n- **RHSA-2025:2545** · Red Hat · fixed in: Red Hat Build of Keycloak · released 2025-03-10 · [advisory](https://access.redhat.com/errata/RHSA-2025:2545)","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":29.7,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}