Incorrect authorization in Keycloak - CVE-2026-9791

 

Incorrect authorization in Keycloak - CVE-2026-9791

Published: September 5, 2026


Vulnerability identifier: #VU146992
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-9791
CWE-ID: CWE-863
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose organization metadata.

The vulnerability exists due to incorrect authorization in Keycloak organization metadata handling when accessing user-facing APIs or requesting an OpenID Connect token with the organization scope. A remote user can access the account API or request an OpenID Connect token with the organization scope to disclose organization metadata.

The issue affects users with existing organization membership after the Organizations feature has been disabled, and the disclosed metadata may lead to incorrect authorization decisions by resource servers.


Affected software

Keycloak
Red Hat build of Keycloak

How to mitigate CVE-2026-9791

Install security update from vendor's website.

Keycloak - update to 26.6.3
Red Hat build of Keycloak - addressed in versions 26.4.13, 26.6.3

External References

Related Security Bulletins