---
id: CVE-2025-1391
title: >-
  A flaw was found in the Keycloak organization feature, which allows the
  incorrect assignment of an organization to a user if their username or email
  matches the organization’s domain pattern
summary: >-
  A flaw was found in the Keycloak organization feature, which allows the
  incorrect assignment of an organization to a user if their username or email
  matches the organization’s domain pattern. This issue occurs at the mapper
  level, leadin…
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'
cwe:
  - CWE-284
vendor: Red Hat
product: keycloak-services
affected:
  - keycloak-services >= 26.0.0 < 26.0.10
  - keycloak-services
  - rhbk/keycloak-operator-bundle (all versions)
  - rhbk/keycloak-rhel9 (all versions)
  - rhbk/keycloak-rhel9-operator (all versions)
published: '2025-02-17'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T06:17:00.010'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-1391'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2025:2544'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:2545'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2025-1391'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2346082'
    label: secalert@redhat.com
  - url: 'https://github.com/keycloak/keycloak/issues/37169'
    label: secalert@redhat.com
  - url: 'https://github.com/keycloak/keycloak/pull/37235'
    label: secalert@redhat.com
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-1391.json
  - url: 'https://www.cve.org/CVERecord?id=CVE-2025-1391'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2025-1391'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2025-02-18T17:17:45.272663Z'
epss: 0.0041
epssPercentile: 0.34964
ingestedAt: '2026-09-21T06:32:37.141Z'
patched:
  - build_of_keycloak 26.0
  - build_of_keycloak
---

## Overview

A flaw was found in the Keycloak organization feature, which allows the incorrect assignment of an organization to a user if their username or email matches the organization’s domain pattern. This issue occurs at the mapper level, leading to misrepresentation in tokens. If an application relies on these claims for authorization, it may incorrectly assume a user belongs to an organization they are not a member of, potentially granting unauthorized access or privileges.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **RHSA-2025:2544** · Red Hat · fixed in: Red Hat build of Keycloak 26.0 · released 2025-03-10 · [advisory](https://access.redhat.com/errata/RHSA-2025:2544)
- **RHSA-2025:2545** · Red Hat · fixed in: Red Hat Build of Keycloak · released 2025-03-10 · [advisory](https://access.redhat.com/errata/RHSA-2025:2545)
