CVE-2026-9791
A flaw was found in Keycloak. An authenticated user with existing organization membership can exploit this flaw by accessing user-facing APIs, such as the account API or by requesting an OpenID Connect (OIDC) token with the 'organization' scope. This allows organization metadata to be disclosed in tokens, even after an administrator has explicitly disabled the Organizations feature, potentially leading to incorrect authorization decisions by resource servers.
Published:May 28, 2026
Last Modified:Jun 26, 2026
EPS:May 28, 2026
EPSS Score:0.00196
CVSS Score:4.3
Affected Products
Vendor
Product
Action
Vendor
Redhat
Product
Build Keycloak
Redhat
Build Keycloak
Vendor
Redhat
Product
Build Of Keycloak
Redhat
Build Of Keycloak
Vendor
Redhat
Product
Keycloak
Redhat
Keycloak
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
No CAPEC recorded yet
Related CVEs
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
