Flaw in Keycloak Allows Information Disclosure via User-Facing APIs
CVE-2026-9791
4.3MEDIUM
What is CVE-2026-9791?
A vulnerability exists in Keycloak that allows authenticated users with organization memberships to exploit weaknesses in user-facing APIs, like the account API or when requesting an OpenID Connect token. This exploitation can lead to unintended disclosure of organization metadata within tokens, posing significant risks if resource servers make erroneous authorization decisions, despite administrative efforts to disable the Organizations feature.
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Evan Hendra (Independent Security Researcher) for reporting this issue.