A flaw was found in Keycloak. A remote attacker can exploit differential error messages during the identity-first login flow when Organizations are enabled. This vulnerability allows an attacker to determine the existence of users, leading to information disclosure through user enumeration.
{
"nvd_published_at": "2026-03-23T11:16:25Z",
"severity": "LOW",
"github_reviewed": true,
"cwe_ids": [
"CWE-209"
],
"github_reviewed_at": "2026-03-26T19:28:56Z"
}