Description
A flaw was found in Keycloak. A remote attacker can exploit differential error messages during the identity-first login flow when Organizations are enabled. This vulnerability allows an attacker to determine the existence of users, leading to information disclosure through user enumeration.
Problem types
Generation of Error Message Containing Sensitive Information
Product status
Timeline
| 2026-03-23: | Reported to Red Hat. |
| 2025-03-23: | Made public. |
References
access.redhat.com/security/cve/CVE-2026-4633
bugzilla.redhat.com/show_bug.cgi?id=2450247 (RHBZ#2450247)