CVE-2026-9791
Keycloak Vulnerable to Incorrect Authorization
4.3
MEDIUM
CVSS 3.1
EPSS 0.21%
Description
A flaw was found in Keycloak. An authenticated user with existing organization membership can exploit this flaw by accessing user-facing APIs, such as the account API or by requesting an OpenID Connect (OIDC) token with the 'organization' scope. This allows organization metadata to be disclosed in tokens, even after an administrator has explicitly disabled the Organizations feature, potentially leading to incorrect authorization decisions by resource servers.
How to fix CVE-2026-9791
To remediate CVE-2026-9791, upgrade the affected package to a fixed version below.
- —upgrade to 26.6.3 or later
- —upgrade to 26.6.3 or later
Is CVE-2026-9791 being exploited?
Low — EPSS is 0.2%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- >= 26.5.0, < 26.6.3
- >= 26.5.0, < 26.6.3
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM4.3 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |