maven package report

Is @keycloak/keycloak-admin-client safe?

1 known vulnerability, worst severity LOW.

cvss
3.1

how bad it is if exploited, out of 10

epss
0.30%

chance of exploitation in the next 30 days

xyz score
1.1

CyberXYZ composite, out of 10

fig. 01 — GHSA-r8jr-wg88-fq5c, the advisory selected below

// advisories

GHSA-r8jr-wg88-fq5c

LOWCVE-2026-2366

A flaw was found in Keycloak. An authorization bypass vulnerability in the Keycloak Admin API allows any authenticated user, even those without administrative privileges, to enumerate the organization memberships of other users. This information disclosure occurs if the attacker knows the victim's unique identifier (UUID) and the Organizations feature is enabled.

Affected
>=26.4.0, <26.4.11
Fixed in
not stated
Weakness
CWE-639
Published
2026-03-12
Source
github

GHSANVDMITRE


// ai model usage

Tracked for PyPI packages. HuggingFace models declare Python dependencies, so maven packages are not covered.


Checked 2026-09-22 at 02:45 UTC. The most recent advisory here was published 2026-03-12. Updated continuously from NVD, GHSA, OSV and CNA feeds.

Think a verdict here is wrong? Tell us — we respond within 2 business days.
Is @keycloak/keycloak-admin-client safe? maven package security report | CyberXYZ