Incorrect authorization in Keycloak - CVE-2026-9791
Published: September 5, 2026
Vulnerability details
The vulnerability allows a remote user to disclose organization metadata.
The vulnerability exists due to incorrect authorization in Keycloak organization metadata handling when accessing user-facing APIs or requesting an OpenID Connect token with the organization scope. A remote user can access the account API or request an OpenID Connect token with the organization scope to disclose organization metadata.
The issue affects users with existing organization membership after the Organizations feature has been disabled, and the disclosed metadata may lead to incorrect authorization decisions by resource servers.
Affected software
Red Hat build of Keycloak
How to mitigate CVE-2026-9791
Red Hat build of Keycloak - addressed in versions 26.4.13, 26.6.3