PT-2026-24939 · Maven+1 · @Keycloak/Keycloak-Admin-Client+4

Joy Gilbert

+1

·

Published

2026-03-12

·

Updated

2026-03-13

·

CVE-2026-2366

CVSS v3.1

3.1

Low

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Keycloak (affected versions not specified)
Description An authorization bypass issue exists in the Keycloak Admin API. This allows any authenticated user, even those without administrative privileges, to enumerate the organization memberships of other users. This information disclosure occurs if the attacker knows the victim’s unique identifier (UUID) and the Organizations feature is enabled. The API endpoint involved is the Keycloak Admin API. The vulnerable parameter is the victim’s unique identifier (UUID).
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

IDOR

Weakness Enumeration

Related Identifiers

CVE-2026-2366
GHSA-R8JR-WG88-FQ5C

Affected Products

@Keycloak/Keycloak-Admin-Client
Red Hat Build Of Keycloak
Red Hat Build Of Keycloak 26.4
Red Hat Build Of Keycloak 26.4.11
Org.Keycloak:Keycloak-Js-Admin-Client