CVE-2026-4633Disclosure(redhat / build_of_keycloak)

LOWCVSS 3.7 · LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch redhat build_of_keycloak systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw was found in Keycloak. A remote attacker can exploit differential error messages during the identity-first login flow when Organizations are enabled. This vulnerability allows an attacker to determine the existence of users, leading to information disclosure through user enumeration.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-209

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • build_of_keycloak

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 4 classified signals
  • Peaked 3d ago at 3 mentions (2026-03-23); latest day: 1
  • 6 total mentions across 4 days

Affected systems

Vendors
Products
build_of_keycloak

1 version affected across 1 product

Deep dive

Activity timeline6 mentions / 4d
01223Mentions · 2026-03-23: 3Mentions · 2026-03-24: 1Mentions · 2026-03-26: 1Mentions · 2026-05-23: 1Patch / Workaround · 2026-03-23: 1Patch / Workaround · 2026-05-23: 1Technical Details · 2026-03-23: 1Technical Details · 2026-03-24: 1Technical Details · 2026-05-23: 103-2303-2403-2605-23
Signal classification2 categories
Disclosure
466.7%
Patch
233.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-233
Disclosure2Patch1
2026-03-241
Disclosure1
2026-03-261
Disclosure1
2026-05-231
Patch1
Full discourse6 posts
  • Volerion@VolerionSec
    Patch

    🚨 CVE-2026-4633: Keycloak leaks valid usernames by returning different errors during login (remote, no login). Attackers can map accounts for further attacks. Disable Organizations or the identity-first login flow until a fix lands. Full advisory ➡️ https://volerion.com/vulnerabilities/CVE-2026-4633 #Keycloak #infosec #AppSec

    Post summary

    The advisory reports a username‑enumeration vulnerability in Keycloak and recommends disabling certain login flows until a patch is available.

    03064668
    55 followersView on X
  • White Rabbitx@TheRabbitPy
    Disclosure

    🛡️ CVE-2026-4633 Keycloak diff error auth bypass (Mar 23). NIST: https://nvd.nist.gov/vuln/detail/CVE-2026-4633

    Post summary

    The tweet announces Keycloak’s authentication bypass flaw (CVE‑2026‑4633) with a link to the NIST NVD entry.

    0004058
    438 followersView on X
  • Stanislav Klevtsov@stansecure
    Patch

    Join my Teleram: https://t.me/securediary 📌 Patch these #CVE: - @Microsoft Defender #PrivEsc (CVE-2026-41091) - #DoS flaw in #Exchange Server (CVE-2026-42897) - @Cisco SD-WAN auth bypass (CVE-2026-20182) - @Linux kernel 9-year-old flaw, reads SSH keys and shadow file (CVE-2026-4633) - @PaloAltoNtwks PAN-OS urgent vuln (CVE-2026-0300) - @nginx #RCE (CVE-2026-42945) - @Drupal Core worker crashes and possible #RCE (PSA-2026-05-18) - #Ivanti EPMM #RCE (CVE-2026-6973) - @gitlab path validation issue (CVE-2026-45571) - @PostgreSQL (CVE-2026-6472 and others) - @valkey_io (CVE-2026-23479)

    Post summary

    The post lists multiple CVEs and urges users to apply patches, offering brief technical descriptors for each but no exploit details or evidence of active attacks.

    00000271
    42 followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    『This issue arises when Organizations are enabled and the identity-first login flow is active.』 CVE-2026-4633 – Keycloak User Enumeration Vulnerability via Differential Error Messages | Volerion Advisory https://volerion.com/vulnerabilities/CVE-2026-4633

    Post summary

    The advisory announces a Keycloak user enumeration vulnerability that exploits differential error messages, providing technical details but no PoC, exploit code, active exploitation, or patch information.

    00000357
    6.7K followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-4633 📊 Severity: 3.7 🚨 Risk Level: Low 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-4633 #CVE-2026-4633 #CVE #Low  #CyberSecurity #InfoSec https://t.co/jTlo3lo6y2

    Post summary

    The post is a concise Twitter alert announcing CVE-2026-4633 with low severity, providing only a reference to the NVD entry and no further technical, exploit, or remediation details.

    0000026
    111 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-4633 User Enumeration Vulnerability in Keycloak Identity-First Login Flow https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-4633

    Post summary

    The text identifies CVE‑2026‑4633 as a user enumeration flaw in Keycloak's identity‑first login flow, but provides no PoC, exploit, patch, or technical specifics.

    0000049
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appredhatbuild_of_keycloak---

Explore more