CVE-2026-4633
ADVISORY - githubSummary
A flaw was found in Keycloak. A remote attacker can exploit differential error messages during the identity-first login flow when Organizations are enabled. This vulnerability allows an attacker to determine the existence of users, leading to information disclosure through user enumeration.
EPSS Score: 0.00049 (0.153)
Common Weakness Enumeration (CWE)
ADVISORY - nist
Generation of Error Message Containing Sensitive Information
ADVISORY - github
Generation of Error Message Containing Sensitive Information
NIST
CREATED
UPDATED
ADVISORY IDCVE-2026-4633
EXPLOITABILITY SCORE
2.2
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)
CVSS SCORE
3.7lowGitHub
CREATED
UPDATED
ADVISORY IDGHSA-rhgq-f8x5-j2jc
EXPLOITABILITY SCORE
2.2
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)