Keycloak Vulnerable to Incorrect Authorization
GHSA-4q93-v92x-p89f · CVE-2026-9791
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
A flaw was found in Keycloak. An authenticated user with existing organization membership can exploit this flaw by accessing user-facing APIs, such as the account API or by requesting an OpenID Connect (OIDC) token with the 'organization' scope. This allows organization metadata to be disclosed in tokens, even after an administrator has explicitly disabled the Organizations feature, potentially leading to incorrect authorization decisions by resource servers.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2026-9791
- WEB https://github.com/keycloak/keycloak/issues/49431
- WEB https://github.com/keycloak/keycloak/pull/49541
- WEB https://github.com/keycloak/keycloak/pull/49678
- WEB https://github.com/keycloak/keycloak/pull/49680
- WEB https://github.com/keycloak/keycloak/commit/0e706e7c83d1e971b48656ad9e674eec6adc225b
- WEB https://github.com/keycloak/keycloak/commit/a77c60f2f3e0793046add44120579871e92553df
- WEB https://github.com/keycloak/keycloak/commit/f19e1f2b4e998116d4e321f50ecf99c0f87b862f
- WEB https://access.redhat.com/errata/RHSA-2026:25097
- WEB https://access.redhat.com/errata/RHSA-2026:25098
- WEB https://access.redhat.com/errata/RHSA-2026:30049
- WEB https://access.redhat.com/errata/RHSA-2026:30050
- WEB https://access.redhat.com/security/cve/CVE-2026-9791
- WEB https://bugzilla.redhat.com/show_bug.cgi?id=2482458
- PACKAGE https://github.com/keycloak/keycloak
Ready to move
Start Securing
Free, no credit card | First findings in minutes