A flaw was found in Keycloak. An authenticated user with existing organization membership can exploit this flaw by accessing user-facing APIs, such as the account API or by requesting an OpenID Connect (OIDC) token with the 'organization' scope. This allows organization metadata to be disclosed in tokens, even after an administrator has explicitly disabled the Organizations feature, potentially leading to incorrect authorization decisions by resource servers.
References
| Link | Resource |
|---|---|
| https://access.redhat.com/security/cve/CVE-2026-9791 | Mitigation Vendor Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2482458 | Issue Tracking Vendor Advisory |
Configurations
History
03 Jun 2026, 18:28
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:redhat:build_of_keycloak:-:*:*:*:-:*:*:* | |
| References | () https://access.redhat.com/security/cve/CVE-2026-9791 - Mitigation, Vendor Advisory | |
| References | () https://bugzilla.redhat.com/show_bug.cgi?id=2482458 - Issue Tracking, Vendor Advisory | |
| First Time |
Redhat
Redhat build Of Keycloak |
28 May 2026, 05:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-28 05:16
Updated : 2026-06-03 18:28
NVD link : CVE-2026-9791
Mitre link : CVE-2026-9791
CVE.ORG link : CVE-2026-9791
JSON object : View
Products Affected
redhat
- build_of_keycloak
CWE
CWE-863
Incorrect Authorization
