CVE-2026-2366
נמוכה 3.1
תיאור (מקור, אנגלית)
A flaw was found in Keycloak. An authorization bypass vulnerability in the Keycloak Admin API allows any authenticated user, even those without administrative privileges, to enumerate the organization memberships of other users. This information disclosure occurs if the attacker knows the victim's unique identifier (UUID) and the Organizations feature is enabled.
מדדים
- CVSS 3.1
-
3.1 (LOW)
מקור הציון: CNA
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N - EPSS — סבירות ניצול
- 0% (אחוזון 000) נכון ל-23/9/2026
- CWE
- CWE-639
מוצרים מושפעים
redhat: build of keycloak
קישורים
- https://access.redhat.com/errata/RHSA-2026:6477 Vendor Advisory
- https://access.redhat.com/errata/RHSA-2026:6478 Vendor Advisory
- https://access.redhat.com/security/cve/CVE-2026-2366 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2439081 ExploitIssue TrackingVendor Advisory