Keycloak OIDC Org Metadata Leak via Authz Bypass
CVE-2026-9791 Published on May 28, 2026
Keycloak-rhel9: organization data leak after feature disabled in keycloak
A flaw was found in Keycloak. An authenticated user with existing organization membership can exploit this flaw by accessing user-facing APIs, such as the account API or by requesting an OpenID Connect (OIDC) token with the 'organization' scope. This allows organization metadata to be disclosed in tokens, even after an administrator has explicitly disabled the Organizations feature, potentially leading to incorrect authorization decisions by resource servers.
Vulnerability Analysis
CVE-2026-9791 can be exploited with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a small impact on confidentiality, a small impact on integrity and availability.
Timeline
Reported to Red Hat.
Made public.
Weakness Type
What is an AuthZ Vulnerability?
The software performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.
CVE-2026-9791 has been classified to as an AuthZ vulnerability or weakness.
Products Associated with CVE-2026-9791
Want to know whenever a new CVE is published for Red Hat Build Keycloak? stack.watch will email you.