PT-2026-32643 · Red Hat · Keycloak

Osidb Bzimport

·

Published

2026-04-14

·

Updated

2026-04-19

·

CVE-2026-37980

CVSS v3.1

6.9

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Keycloak (affected versions not specified)
Description A Stored Cross-Site Scripting (XSS) issue exists in the organization selection login page. A remote attacker possessing manage-realm or manage-organizations administrative privileges can execute arbitrary JavaScript in a user's browser. This occurs because the organization.alias variable is placed into an inline JavaScript onclick handler without proper sanitization. Successful exploitation may lead to session theft or unauthorized account actions.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-37980
GHSA-M32F-8VH9-2HH3

Affected Products

Keycloak