Low severity3.7NVD Advisory· Published Mar 23, 2026· Updated Apr 1, 2026
CVE-2026-4633
CVE-2026-4633
Description
A flaw was found in Keycloak. A remote attacker can exploit differential error messages during the identity-first login flow when Organizations are enabled. This vulnerability allows an attacker to determine the existence of users, leading to information disclosure through user enumeration.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.keycloak:keycloak-servicesMaven | >= 26.5.0, < 26.6.1 | 26.6.1 |
org.keycloak:keycloak-servicesMaven | < 26.4.12 | 26.4.12 |
Affected products
8- cpe:2.3:a:redhat:build_of_keycloak:-:*:*:*:-:*:*:*
- osv-coords7 versionspkg:apk/chainguard/keycloak-26.5pkg:apk/chainguard/keycloak-26.5-iamguarded-compatpkg:apk/chainguard/keycloak-fips-26.5pkg:apk/chainguard/keycloak-fips-26.5-iamguarded-fipspkg:apk/wolfi/keycloak-26.5pkg:apk/wolfi/keycloak-26.5-iamguarded-compatpkg:maven/org.keycloak/keycloak-services
< 26.5.7-r0+ 6 more
- (no CPE)range: < 26.5.7-r0
- (no CPE)range: < 26.5.7-r0
- (no CPE)range: < 26.5.6-r4
- (no CPE)range: < 26.5.6-r4
- (no CPE)range: < 26.5.7-r0
- (no CPE)range: < 26.5.7-r0
- (no CPE)range: >= 26.5.0, < 26.6.0
Patches
Vulnerability mechanics
References
8- bugzilla.redhat.com/show_bug.cginvdExploitIssue TrackingVendor AdvisoryWEB
- access.redhat.com/security/cve/CVE-2026-4633nvdVendor AdvisoryWEB
- github.com/advisories/GHSA-rhgq-f8x5-j2jcghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-4633ghsaADVISORY
- github.com/keycloak/keycloak/commit/b137016cc6dcfd9f59b2aa2e6d73af8b0ebf7c6eghsaWEB
- github.com/keycloak/keycloak/commit/b4558a874fa79341404ae4d2d8f240f22bfed340ghsaWEB
- github.com/keycloak/keycloak/issues/47619ghsaWEB
- github.com/keycloak/keycloak/pull/47635ghsaWEB
News mentions
0No linked articles in our index yet.