Vulnerability Description
A flaw was found in the organization management component of Keycloak. A delegated administrator with permission to manage organizations can create an invitation for a non-existent email address and then retrieve the secret registration link directly through the application programming interface. By using this link, the administrator can create new user accounts and add them to the organization without having the required user management permissions or access to the invited email account. This allows an administrator to bypass security boundaries and add unauthorized members to an organization.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Build Of Keycloak | - |
Related Weaknesses (CWE)
References
- https://access.redhat.com/security/cve/CVE-2026-16072Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2501721Issue TrackingVendor Advisory
FAQ
What is CVE-2026-16072?
CVE-2026-16072 is a vulnerability with a CVSS score of 4.9 (MEDIUM). A flaw was found in the organization management component of Keycloak. A delegated administrator with permission to manage organizations can create an invitation for a non-existent email address and t...
How severe is CVE-2026-16072?
CVE-2026-16072 has been rated MEDIUM with a CVSS base score of 4.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-16072?
Check the references section above for vendor advisories and patch information. Affected products include: Redhat Build Of Keycloak.