Flaw in Keycloak Allows Information Disclosure via User-Facing APIs
CVE-2026-9791

4.3MEDIUM

Key Information:

Vendor

Red Hat

Vendor
CVE Published:
28 May 2026

What is CVE-2026-9791?

A vulnerability exists in Keycloak that allows authenticated users with organization memberships to exploit weaknesses in user-facing APIs, like the account API or when requesting an OpenID Connect token. This exploitation can lead to unintended disclosure of organization metadata within tokens, posing significant risks if resource servers make erroneous authorization decisions, despite administrative efforts to disable the Organizations feature.

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Evan Hendra (Independent Security Researcher) for reporting this issue.
.