CVE-2026-4633 identifies a low-severity information disclosure vulnerability in Keycloak when Organizations are enabled. A remote attacker can exploit differential error messages during the identity-first login flow to determine the existence of users, leading to user enumeration. While network-exploitable, the attack complexity is high, resulting in a CVSS score of 3.7. There is currently no evidence of active exploitation, public exploit code, or significant community attention for this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:redhat:build_of_keycloak:-:*:*:*:-:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.