---
id: CVE-2026-2366
title: A flaw was found in Keycloak
summary: >-
  A flaw was found in Keycloak. An authorization bypass vulnerability in the
  Keycloak Admin API allows any authenticated user, even those without
  administrative privileges, to enumerate the organization memberships of other
  users. This inf…
severity: low
cvss: 3.1
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-639
vendor: redhat
product: build_of_keycloak
affected:
  - 'build_of_keycloak >= 26.4, < 26.4.11'
patched:
  - build_of_keycloak 26.4.11
published: '2026-03-12'
updated: '2026-08-18'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-2366'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2026:6477'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:6478'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2026-2366'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2439081'
    label: secalert@redhat.com
tags:
  - nvd
epss: 0.00268
epssPercentile: 0.16846
ingestedAt: '2026-08-18T17:20:35.294Z'
---

## Overview

A flaw was found in Keycloak. An authorization bypass vulnerability in the Keycloak Admin API allows any authenticated user, even those without administrative privileges, to enumerate the organization memberships of other users. This information disclosure occurs if the attacker knows the victim's unique identifier (UUID) and the Organizations feature is enabled.

## Affected

- `build_of_keycloak >= 26.4, < 26.4.11`

## Remediation

Upgrade past the affected range:

- `build_of_keycloak 26.4.11`
