Back

LOW

Keycloak: keycloak: information disclosure via authorization bypass in admin api

Published Mar 12, 2026

Description

A flaw was found in Keycloak. An authorization bypass vulnerability in the Keycloak Admin API allows any authenticated user, even those without administrative privileges, to enumerate the organization memberships of other users. This information disclosure occurs if the attacker knows the victim's unique identifier (UUID) and the Organizations feature is enabled.

Affected products

Remediation

Vendor solution

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Red Hat statement

This LOW impact authorization bypass in the Keycloak Admin API allows an authenticated user to enumerate organization memberships of other users if their UUID is known. This occurs when the Organizations feature is enabled.

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Metrics

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Mar 12, 2026
Updated Apr 2, 2026
Reserved Feb 11, 2026
CISA Vulnrichment
Updated Mar 12, 2026
NVD
Status Analyzed
Modified Aug 18, 2026
Red Hat
Severity Low
Public date Feb 11, 2026
GHSA-R8JR-WG88-FQ5C