CVE-2026-2366Low· 3.1▾ SunlitA flaw was found in Keycloak. An authorization bypass vulnerability in the Keycloak Admin API allows any authenticated user, even those without administrative privileges, to enumerate the organization memberships of other users. This inf…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 17.1 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 18.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
A flaw was found in Keycloak. An authorization bypass vulnerability in the Keycloak Admin API allows any authenticated user, even those without administrative privileges, to enumerate the organization memberships of other users. This information disclosure occurs if the attacker knows the victim's unique identifier (UUID) and the Organizations feature is enabled.
build_of_keycloak >= 26.4, < 26.4.11Upgrade past the affected range:
build_of_keycloak 26.4.11Connected by shared product, vendor, weakness, or advisory.
CVE-2026-3429Medium· 4.2A flaw was identified in the Account REST API of Keycloak that allows a user authenticated at a lower security level to perform sensitive actions intended only for higher-assurance sessions
CVE-2026-17059Medium· 6.5A flaw was found in the role-users endpoint of the keycloak-services library, which is the core component of the Keycloak identity and access management solution
CVE-2026-15945Medium· 4.3A flaw was found in the group search functionality of the Keycloak server's administrative API
CVE-2026-16105Medium· 4.9A flaw was found in the RoleContainerResource component of Keycloak
CVE-2025-3910Medium· 5.4A flaw was found in Keycloak
CVE-2026-9796Medium· 6.5A flaw was found in Keycloak