Junglewise Threat Intelligence

CVE-2026-2366: A flaw was found in Keycloak. An authorization bypass vulnerability in the Keycloak Admin API allows any authenticated user, even those with

CVE-2026-2366 · Severity: low · CVSS 3.1 · Published 2026-03-12

Technologies: Keycloak. Vendors: Keycloak, Maven, npm.

Executive brief

Keycloak is an open-source identity and access management platform used to manage user authentication and authorization. An authenticated user without administrative privileges can view the organization memberships of other users in Keycloak deployments that have the Organizations feature enabled, as long as the attacker knows the target user's unique identifier. This allows unauthorized information disclosure about organizational structure and user affiliations.

Technical details

The vulnerability is an authorization bypass (CWE-639) in the Keycloak Admin API where privilege checks are insufficiently enforced. An authenticated user can enumerate organization memberships of arbitrary users via the Admin API by providing the target user's UUID, without requiring administrative rights. The Organizations feature must be enabled for the vulnerability to be exploitable. Attack vector is network-based and requires only a low privilege (authenticated) account and knowledge of the victim's UUID. An attacker can disclosure sensitive information about user-to-organization mappings. Patches are available in Keycloak 26.4.11, 26.5.6, and 26.6.0+.

Affected products

  • Keycloak Keycloak through 26.5.5
  • Keycloak keycloak-admin-client through 26.5.5

Timeline

  • 2026-03-12: disclosed: Advisory published
  • 2026-03-12: patched: Patches available in versions 26.4.11, 26.5.6, and 26.6.0+

References

Related threats