A flaw was found in Keycloak. An authorization bypass vulnerability in the Keycloak Admin API allows any authenticated user, even those without administrative privileges, to enumerate the organization memberships of other users. This information disclosure occurs if the attacker knows the victim's unique identifier (UUID) and the Organizations feature is enabled.
Metrics
Affected Vendors & Products
References
History
Thu, 12 Mar 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 12 Mar 2026 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | No description is available for this CVE. | A flaw was found in Keycloak. An authorization bypass vulnerability in the Keycloak Admin API allows any authenticated user, even those without administrative privileges, to enumerate the organization memberships of other users. This information disclosure occurs if the attacker knows the victim's unique identifier (UUID) and the Organizations feature is enabled. |
| Title | keycloak: Keycloak: Information disclosure via authorization bypass in Admin API | Keycloak: keycloak: information disclosure via authorization bypass in admin api |
| First Time appeared |
Redhat
Redhat build Keycloak |
|
| CPEs | cpe:/a:redhat:build_keycloak: | |
| Vendors & Products |
Redhat
Redhat build Keycloak |
|
| References |
|
Mon, 16 Feb 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Keycloak
Keycloak keycloak |
|
| Vendors & Products |
Keycloak
Keycloak keycloak |
Thu, 12 Feb 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | No description is available for this CVE. | |
| Title | keycloak: Keycloak: Information disclosure via authorization bypass in Admin API | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published: 2026-03-12T10:54:31.990Z
Updated: 2026-03-12T13:14:43.160Z
Reserved: 2026-02-11T19:59:15.446Z
Link: CVE-2026-2366
Updated: 2026-03-12T13:14:36.601Z
Status : Awaiting Analysis
Published: 2026-03-12T11:15:55.860
Modified: 2026-03-12T21:07:53.427
Link: CVE-2026-2366