A flaw was found in the Keycloak organization feature, which allows the incorrect assignment of an organization to a user if their username or email matches the organization’s domain pattern. This issue occurs at the mapper level, leading to misrepresentation in tokens. If an application relies on these claims for authorization, it may incorrectly assume a user belongs to an organization they are not a member of, potentially granting unauthorized access or privileges.
                
            Metrics
Affected Vendors & Products
References
        History
                    Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | epss 
 | epss 
 | 
Mon, 10 Mar 2025 18:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| CPEs | cpe:/a:redhat:build_keycloak:26.0::el9 | |
| References |  | 
Mon, 10 Mar 2025 18:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| CPEs | cpe:/a:redhat:build_keycloak:26 | |
| References |  | 
Tue, 18 Feb 2025 20:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | ssvc 
 | 
Mon, 17 Feb 2025 14:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | No description is available for this CVE. | A flaw was found in the Keycloak organization feature, which allows the incorrect assignment of an organization to a user if their username or email matches the organization’s domain pattern. This issue occurs at the mapper level, leading to misrepresentation in tokens. If an application relies on these claims for authorization, it may incorrectly assume a user belongs to an organization they are not a member of, potentially granting unauthorized access or privileges. | 
| Title | org.keycloak/keycloak-services: Improper Authorization in Keycloak Organization Mapper Allows Unauthorized Organization Claims | Keycloak-services: improper authorization in keycloak organization mapper allows unauthorized organization claims | 
| First Time appeared | Redhat Redhat build Keycloak | |
| CPEs | cpe:/a:redhat:build_keycloak: | |
| Vendors & Products | Redhat Redhat build Keycloak | |
| References |  | 
Mon, 17 Feb 2025 14:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | No description is available for this CVE. | |
| Title | org.keycloak/keycloak-services: Improper Authorization in Keycloak Organization Mapper Allows Unauthorized Organization Claims | |
| Weaknesses | CWE-284 | |
| References |  | |
| Metrics | threat_severity 
 | cvssV3_1 
 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: redhat
Published: 2025-02-17T14:01:35.354Z
Updated: 2025-08-30T21:17:39.947Z
Reserved: 2025-02-17T08:56:42.702Z
Link: CVE-2025-1391
 Vulnrichment
                        Vulnrichment
                    Updated: 2025-02-18T17:17:52.617Z
 NVD
                        NVD
                    Status : Awaiting Analysis
Published: 2025-02-17T14:15:08.413
Modified: 2025-03-10T19:15:39.860
Link: CVE-2025-1391
 Redhat
                        Redhat