Keycloak's identity-first login flow exposes user information
Low severity
GitHub Reviewed
Published
Mar 23, 2026
to the GitHub Advisory Database
•
Updated Jun 17, 2026
Package
Affected versions
>= 26.5.0, < 26.6.1
< 26.4.12
Patched versions
26.6.1
26.4.12
Description
Published by the National Vulnerability Database
Mar 23, 2026
Published to the GitHub Advisory Database
Mar 23, 2026
Reviewed
Mar 26, 2026
Last updated
Jun 17, 2026
A flaw was found in Keycloak. A remote attacker can exploit differential error messages during the identity-first login flow when Organizations are enabled. This vulnerability allows an attacker to determine the existence of users, leading to information disclosure through user enumeration.
References