THREAT OPS › Threat News › [NVD] CVE-2026-16072 (MEDIUM 4.9) — A flaw was found in the organization management component of Keycloak. A delegated administrator with permission to manage organizations can create an invitation for a non-existent email address and then retrieve the secret registration link directly through the application progr
[NVD] CVE-2026-16072 (MEDIUM 4.9) — A flaw was found in the organization management component of Keycloak. A delegated administrator with permission to manage organizations can create an invitation for a non-existent email address and then retrieve the secret registration link directly through the application progr
CVE-2026-16072 CVSS: 4.9 MEDIUM Published: 2026-07-17T14:17:21.860
A flaw was found in the organization management component of Keycloak. A delegated administrator with permission to manage organizations can create an invitation for a non-existent email address and then retrieve the secret registration link directly through the application programming interface. By using this link, the administra
MITRE ATT&CK techniques
- Email AccountT1087.003
Indicators of compromise
- CVE-2026-16072cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-16072