Improper access control in Keycloak - CVE-2026-16072
Published: July 17, 2026 / Updated: September 5, 2026
Vulnerability details
The vulnerability allows a remote user to add unauthorized members to an organization.
The vulnerability exists due to improper access control in the organization management component when creating invitations for non-existent email addresses and retrieving their secret registration links through the application programming interface. A remote privileged user can create an invitation and retrieve its secret registration link to add unauthorized members to an organization.
Exploitation requires permission to manage organizations.