Incorrect authorization in Keycloak - CVE-2026-2366
Published: September 10, 2026
Vulnerability details
The vulnerability allows a remote user to disclose user organization membership information.
The vulnerability exists due to incorrect authorization in the organizations feature when handling organization membership queries. A remote user can use an unprivileged token to enumerate user organization memberships to disclose user organization membership information.
Affected software
Red Hat build of Keycloak
How to mitigate CVE-2026-2366
Red Hat build of Keycloak - update to 26.4.11