Executive brief
Keycloak, an open-source identity and access management solution, is vulnerable to a user enumeration flaw when the Organizations feature is enabled. An attacker can use subtle differences in error messages during the login process to confirm whether specific usernames exist in the system. This information can be used to facilitate more targeted attacks, such as password guessing or phishing.
Technical details
A flaw exists in Keycloak's identity-first login flow (CWE-209) when the Organizations feature is active. By observing differential error messages returned by the server, a remote, unauthenticated attacker can determine if a specific user exists within the system. The attack complexity is considered high as it requires specific configuration (Organizations enabled) and precise analysis of server responses. This vulnerability allows for user enumeration, which can be a precursor to brute-force or social engineering attacks. Patches are available in versions 26.4.12 and 26.6.1.
Affected products
- Keycloak Keycloak >= 26.5.0, < 26.6.1; < 26.4.12
Timeline
- 2026-03-23: disclosed
- 2026-03-23: advisory