User enumeration via differential error messages in Organizations + identity-first login flow. Existing users receive "Invalid Password" while non-existent users receive "Invalid username or password." Requirements to exploit: Organizations enabled on realm, identity-first login flow active, network access to login endpoint. Steps to reproduce: 1. Create a realm and enable Organizations. 2. Create an organization and add a user with a known password. 3. Navigate to /realms/[realm]/account/. 4. Enter a non-existent username, click "Sign in," enter any password, and submit. 5. Observe error: "Invalid username or password." 6. Repeat with an existing username. 7. Observe error: "Invalid Password." 8. The differential response confirms user existence.