CVE-2026-2366Disclosure(redhat / build_of_keycloak)

LOWCVSS 3.1 · LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw was found in Keycloak. An authorization bypass vulnerability in the Keycloak Admin API allows any authenticated user, even those without administrative privileges, to enumerate the organization memberships of other users. This information disclosure occurs if the attacker knows the victim's unique identifier (UUID) and the Organizations feature is enabled.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-639

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • build_of_keycloak

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-03-12); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
build_of_keycloak

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-12: 1Mentions · 2026-03-13: 1Technical Details · 2026-03-12: 1Technical Details · 2026-03-13: 103-1203-13
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-2366 A flaw was found in Keycloak. An authorization bypass vulnerability in the Keycloak Admin API allows any authenticated user, even those without administrative privilege… https://www.cve.org/CVERecord?id=CVE-2026-2366

    Post summary

    This post announces an authorization bypass vulnerability (CVE-2026-2366) in Keycloak that allows authenticated non‑admin users to perform admin actions, with details available in the CVE record but no PoC, exploit, or patch information disclosed.

    00000160
    56.7K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-2366 - Keycloak: keycloak: information disclosure via authorization bypass in admin api Intel Report: https://ift.tt/0HwqdA6

    Post summary

    The alert announces CVE-2026-2366, an information disclosure flaw in Keycloak caused by a user‑rights bypass in the admin API, and points to an Intel report for more details.

    0000033
    342 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appredhatbuild_of_keycloak---

Explore more