A flaw was found in Keycloak. A remote attacker can exploit differential error messages during the identity-first login flow when Organizations are enabled. This vulnerability allows an attacker to determine the existence of users, leading to information disclosure through user enumeration.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-03-23 11:16
Updated : 2026-03-23 14:31
NVD link : CVE-2026-4633
Mitre link : CVE-2026-4633
CVE.ORG link : CVE-2026-4633
JSON object : View
Products Affected
No product.
CWE
CWE-209
Generation of Error Message Containing Sensitive Information
