Maven · @Keycloak/Keycloak-Admin-Client · CVE-2026-2366
**Name of the Vulnerable Software and Affected Versions**
Keycloak (affected versions not specified)
**Description**
An authorization bypass issue exists in the Keycloak Admin API. This allows any authenticated user, even those without administrative privileges, to enumerate the organization memberships of other users. This information disclosure occurs if the attacker knows the victim’s unique identifier (UUID) and the Organizations feature is enabled. The API endpoint involved is the Keycloak Admin API. The vulnerable parameter is the victim’s unique identifier (`UUID`).
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.