User Enumeration Risk in Keycloak by Red Hat
CVE-2026-4633
3.7LOW
What is CVE-2026-4633?
A remote attacker can exploit a flaw found in Keycloak's identity-first login flow when Organizations are enabled. By leveraging differential error messages, the attacker is capable of enumerating user accounts, which may lead to unauthorized information disclosure. This vulnerability underscores the importance of tightening security measures to protect user identities from potential exploitation.