A flaw was found in Keycloak, specifically in the organization selection login page. A remote attacker with `manage-realm` or `manage-organizations` administrative privileges can exploit a Stored Cross-Site Scripting (XSS) vulnerability. This flaw occurs because the `organization.alias` is placed into an inline JavaScript `onclick` handler, allowing a crafted JavaScript payload to execute in a user's browser when they view the login page. Successful exploitation enables arbitrary JavaScript execution, potentially leading to session theft, unauthorized account actions, or further attacks against users of the affected realm.
References
| Link | Resource |
|---|---|
| https://access.redhat.com/security/cve/CVE-2026-37980 | Mitigation Vendor Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2455325 | Issue Tracking Vendor Advisory |
Configurations
History
02 Jun 2026, 17:37
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:redhat:build_of_keycloak:-:*:*:*:-:*:*:* | |
| First Time |
Redhat
Redhat build Of Keycloak |
|
| References | () https://access.redhat.com/security/cve/CVE-2026-37980 - Mitigation, Vendor Advisory | |
| References | () https://bugzilla.redhat.com/show_bug.cgi?id=2455325 - Issue Tracking, Vendor Advisory |
14 Apr 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-14 15:16
Updated : 2026-06-02 17:37
NVD link : CVE-2026-37980
Mitre link : CVE-2026-37980
CVE.ORG link : CVE-2026-37980
JSON object : View
Products Affected
redhat
- build_of_keycloak
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
