Improper access control in Keycloak - CVE-2026-16072

 

Improper access control in Keycloak - CVE-2026-16072

Published: July 17, 2026 / Updated: September 5, 2026


Vulnerability identifier: #VU146966
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-16072
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to add unauthorized members to an organization.

The vulnerability exists due to improper access control in the organization management component when creating invitations for non-existent email addresses and retrieving their secret registration links through the application programming interface. A remote privileged user can create an invitation and retrieve its secret registration link to add unauthorized members to an organization.

Exploitation requires permission to manage organizations.


Affected software

Keycloak

How to mitigate CVE-2026-16072

Install security update from vendor's website.

Keycloak - update to 26.7.3

External References

Related Security Bulletins