Vulnerability Description
A flaw was found in Keycloak. An authorization bypass vulnerability in the Keycloak Admin API allows any authenticated user, even those without administrative privileges, to enumerate the organization memberships of other users. This information disclosure occurs if the attacker knows the victim's unique identifier (UUID) and the Organizations feature is enabled.
CVSS Score
LOW
Related Weaknesses (CWE)
References
- https://access.redhat.com/errata/RHSA-2026:6477
- https://access.redhat.com/errata/RHSA-2026:6478
- https://access.redhat.com/security/cve/CVE-2026-2366
- https://bugzilla.redhat.com/show_bug.cgi?id=2439081
FAQ
What is CVE-2026-2366?
CVE-2026-2366 is a vulnerability with a CVSS score of 3.1 (LOW). A flaw was found in Keycloak. An authorization bypass vulnerability in the Keycloak Admin API allows any authenticated user, even those without administrative privileges, to enumerate the organization...
How severe is CVE-2026-2366?
CVE-2026-2366 has been rated LOW with a CVSS base score of 3.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-2366?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.