PT-2026-24583 · Red Hat+1 · Red Hat Build Of Keycloak+4

Drak3Hft7

·

Published

2026-03-11

·

Updated

2026-05-07

·

CVE-2026-3911

CVSS v3.1

2.7

Low

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Keycloak (affected versions not specified)
Description An issue exists in Keycloak where an authenticated user possessing the view-users role can access and retrieve user attributes intended to be hidden. This occurs through exploitation of a flaw within the UserResource component by accessing a specific administrative endpoint. This unauthorized access leads to information disclosure of sensitive user data.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

CVE-2026-3911
GHSA-XH32-C9WX-PHRP

Affected Products

Red Hat Build Of Keycloak
Red Hat Build Of Keycloak 26.4
Red Hat Build Of Keycloak 26.4.11
Build Of Keycloak
Org.Keycloak:Keycloak-Services