Feed/CVE-2026-9791
CVE-2026-9791MEDIUMCVSS 4.3

Keycloak Vulnerable to Incorrect Authorization

Published May 28, 2026·Updated Jul 1, 2026

NVD Description

A flaw was found in Keycloak. An authenticated user with existing organization membership can exploit this flaw by accessing user-facing APIs, such as the account API or by requesting an OpenID Connect (OIDC) token with the 'organization' scope. This allows organization metadata to be disclosed in tokens, even after an administrator has explicitly disabled the Organizations feature, potentially leading to incorrect authorization decisions by resource servers.

Affected Packages (2)

org.keycloak:keycloak-servicesMAVEN
From 26.5.0
Fixed in 26.6.3
org.keycloak:keycloak-server-spi-privateMAVEN
From 26.5.0
Fixed in 26.6.3

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free