User Enumeration Risk in Keycloak by Red Hat
CVE-2026-4633

3.7LOW

Key Information:

Vendor

Red Hat

Vendor
CVE Published:
23 March 2026

What is CVE-2026-4633?

A remote attacker can exploit a flaw found in Keycloak's identity-first login flow when Organizations are enabled. By leveraging differential error messages, the attacker is capable of enumerating user accounts, which may lead to unauthorized information disclosure. This vulnerability underscores the importance of tightening security measures to protect user identities from potential exploitation.

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.