Project Subscriptions
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-r8jr-wg88-fq5c | Keycloak vulnerable to authorization bypass via the Admin API |
Solution
No solution given by the vendor.
Workaround
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Thu, 12 Mar 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 12 Mar 2026 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | No description is available for this CVE. | A flaw was found in Keycloak. An authorization bypass vulnerability in the Keycloak Admin API allows any authenticated user, even those without administrative privileges, to enumerate the organization memberships of other users. This information disclosure occurs if the attacker knows the victim's unique identifier (UUID) and the Organizations feature is enabled. |
| Title | keycloak: Keycloak: Information disclosure via authorization bypass in Admin API | Keycloak: keycloak: information disclosure via authorization bypass in admin api |
| First Time appeared |
Redhat
Redhat build Keycloak |
|
| CPEs | cpe:/a:redhat:build_keycloak: | |
| Vendors & Products |
Redhat
Redhat build Keycloak |
|
| References |
|
Mon, 16 Feb 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Keycloak
Keycloak keycloak |
|
| Vendors & Products |
Keycloak
Keycloak keycloak |
Thu, 12 Feb 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | No description is available for this CVE. | |
| Title | keycloak: Keycloak: Information disclosure via authorization bypass in Admin API | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-03-12T13:14:43.160Z
Reserved: 2026-02-11T19:59:15.446Z
Link: CVE-2026-2366
Updated: 2026-03-12T13:14:36.601Z
Status : Awaiting Analysis
Published: 2026-03-12T11:15:55.860
Modified: 2026-03-12T21:07:53.427
Link: CVE-2026-2366
OpenCVE Enrichment
Updated: 2026-02-16T12:03:31Z
Github GHSA