CVE-2026-4633

LOW

Keycloak: keycloak: user enumeration via differential error messages

Title source: cna
STIX 2.1

Description

A flaw was found in Keycloak. A remote attacker can exploit differential error messages during the identity-first login flow when Organizations are enabled. This vulnerability allows an attacker to determine the existence of users, leading to information disclosure through user enumeration.

Scores

CVSS v3 3.7
EPSS 0.0004
EPSS Percentile 12.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-209
Status published
Products (3)
org.keycloak/keycloak-services 0Maven
Red Hat/Red Hat Build of Keycloak
redhat/build_of_keycloak
Published Mar 23, 2026
Tracked Since Mar 23, 2026