Bug 2501721 (CVE-2026-16072) - CVE-2026-16072 keycloak-services: keycloak-services: Organization invitation link exposure allows unauthorized member creation
Summary: CVE-2026-16072 keycloak-services: keycloak-services: Organization invitation ...
Keywords:
Status: NEW
Alias: CVE-2026-16072
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-07-17 13:26 UTC by OSIDB Bzimport
Modified: 2026-07-17 13:36 UTC (History)
28 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-07-17 13:26:34 UTC
A permission bypass vulnerability was identified in the Keycloak organization REST API. The flaw exists in how pending organization invitations are handled. A user granted the manage-organizations permission, but lacking the manage-users permission, can initiate an invitation for an arbitrary email address. The API response for listing pending invitations includes the inviteLink, which contains a bearer token for registration. An attacker can retrieve this link and access it directly to register a new managed member. This bypasses the requirement for the manage-users permission and skips the intended email ownership verification step. Successful exploitation allows a delegated administrator to create new managed user accounts and associate them with an organization without proper authorization.


Note You need to log in before you can comment on or make changes to this bug.