CVE-2026-2366: Keycloak: keycloak: information disclosure via authorization bypass in admin api

Published Feb 11, 2026
·
Updated

A flaw was found in Keycloak. An authorization bypass vulnerability in the Keycloak Admin API allows any authenticated user, even those without administrative privileges, to enumerate the organization memberships of other users. This information disclosure occurs if the attacker knows the victim's unique identifier (UUID) and the Organizations feature is enabled.

Other sources

Summary

An authorization bypass exists in the Keycloak Admin API where the endpoint /admin/realms/

{realm}/organizations/members/{member-id}/organizations fails to perform necessary permission checks. This allows any authenticated user, regardless of their roles or administrative privileges, to enumerate the organization memberships of any other user if their unique identifier (UUID) is known.

Requirements to exploit The Organizations feature must be enabled (which is the default in recent versions). The attacker must possess a valid access token for the realm. The attacker must know the UUID of the victim user. Component affected

org.keycloak.services.resources.admin.organizations

Version affected: 26.5.1

Patch available: No

CVSS: 3.1 (Low) CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N

Embargo: No

Acknowledgement: Reynaldo Immanuel, Joy Gilbert

Steps to reproduce Enable the Organizations feature and create multiple organizations (e.g., orgA, orgB). Create a victim user and assign them to several organizations Create a low-privileged "attacker" user with no administrative roles. Obtain an OIDC access token for the low-privileged user. Execute a GET request to /admin/realms/{realm} /organizations/members/

{victim-id} /organizations using the low-privileged token.

Observe that the server returns a 200 OK response containing a full list of the victim's organization memberships instead of the expected 403 Forbidden.

Red Hat

Affected Software

4 affected components
Keycloak Keycloak
maven/org.keycloak:keycloak-js-admin-client<=26.5.5
npm/@keycloak/keycloak-admin-client<=26.5.5
redhat Build Of Keycloak>=26.4<26.4.11

Event History

Feb 11, 2026
Data Sourced
via Red Hat·07:58 PM
DescriptionSeverityAffected Software
Mar 12, 2026
CVE Published
via MITRE·10:54 AM
Data Sourced
via MITRE·10:54 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 AM
Affected Software
Advisory Published
via GitHub·12:30 PM
Data Sourced
via GitHub·12:30 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2026-2366?

CVE-2026-2366 is classified as a medium severity vulnerability.

2

How do I fix CVE-2026-2366?

To fix CVE-2026-2366, update Keycloak to version 26.5.6 or later.

3

What systems are affected by CVE-2026-2366?

CVE-2026-2366 affects Keycloak versions up to and including 26.5.5.

4

What is the exploit scenario for CVE-2026-2366?

CVE-2026-2366 allows authenticated users to gain access to organization memberships they should not have permissions for.

5

How can I determine if my installation is vulnerable to CVE-2026-2366?

Check your Keycloak version; if it is 26.5.5 or earlier, it is vulnerable to CVE-2026-2366.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203