SEPTEMBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-16072

MEDIUM · CVSS 4.9 EPSS 0.20%

Source: NVD + CISA KEV + EPSS · Published 2026-07-17 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The vulnerability exists in the organization management component of Keycloak, where a delegated administrator can generate an invitation for a non-existent email address and obtain a secret registration link via the API. This exploit enables the administrator to create user accounts and add them to the organization without proper permissions, effectively bypassing security controls. Organizations using Keycloak should prioritize addressing this issue to prevent unauthorized access and maintain the integrity of their user management processes.

CVE
CVE-2026-16072
Severity
MEDIUM
CVSS
4.9
EPSS
0.20%

Original NVD Description

A flaw was found in the organization management component of Keycloak. A delegated administrator with permission to manage organizations can create an invitation for a non-existent email address and then retrieve the secret registration link directly through the application programming interface. By using this link, the administrator can create new user accounts and add them to the organization without having the required user management permissions or access to the invited email account. This allows an administrator to bypass security boundaries and add unauthorized members to an organization.

Related CVEs

Other vulnerabilities affecting the same vendor(s)