ZeroHour

CVE-2026-4633

PoC
CVSS 3.1
3.7 low
EPSS
<1%p25
Published
()
Modified
Description

A flaw was found in Keycloak. A remote attacker can exploit differential error messages during the identity-first login flow when Organizations are enabled. This vulnerability allows an attacker to determine the existence of users, leading to information disclosure through user enumeration.

Vendors
redhat
Products
build of keycloak
Weakness
CWE-209
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.