THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-16072 (MEDIUM 4.9) — A flaw was found in the organization management component of Keycloak. A delegated administrator with permission to manage organizations can create an invitation for a non-existent email address and then retrieve the secret registration link directly through the application progr

[NVD] CVE-2026-16072 (MEDIUM 4.9) — A flaw was found in the organization management component of Keycloak. A delegated administrator with permission to manage organizations can create an invitation for a non-existent email address and then retrieve the secret registration link directly through the application progr

mednvdPublished 2026-07-17

CVE-2026-16072 CVSS: 4.9 MEDIUM Published: 2026-07-17T14:17:21.860

A flaw was found in the organization management component of Keycloak. A delegated administrator with permission to manage organizations can create an invitation for a non-existent email address and then retrieve the secret registration link directly through the application programming interface. By using this link, the administra

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-16072