CVE-2026-3911

A flaw was found in Keycloak. An authenticated user with the view-users role could exploit a vulnerability in the UserResource component. By accessing a specific administrative endpoint, this user could improperly retrieve user attributes that were configured to be hidden. This unauthorized information disclosure could expose sensitive user data.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:redhat:build_of_keycloak:-:*:*:*:text-only:*:*:*
cpe:2.3:a:redhat:build_of_keycloak:26.4:*:*:*:*:*:*:*
cpe:2.3:a:redhat:build_of_keycloak:26.4.11:*:*:*:*:*:*:*

History

07 May 2026, 18:30

Type Values Removed Values Added
References () https://access.redhat.com/errata/RHSA-2026:6477 - () https://access.redhat.com/errata/RHSA-2026:6477 - Vendor Advisory
References () https://access.redhat.com/errata/RHSA-2026:6478 - () https://access.redhat.com/errata/RHSA-2026:6478 - Vendor Advisory
References () https://access.redhat.com/security/cve/CVE-2026-3911 - () https://access.redhat.com/security/cve/CVE-2026-3911 - Vendor Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=2446392 - () https://bugzilla.redhat.com/show_bug.cgi?id=2446392 - Issue Tracking
CWE NVD-CWE-noinfo
First Time Redhat
Redhat build Of Keycloak
CPE cpe:2.3:a:redhat:build_of_keycloak:26.4:*:*:*:*:*:*:*
cpe:2.3:a:redhat:build_of_keycloak:26.4.11:*:*:*:*:*:*:*
cpe:2.3:a:redhat:build_of_keycloak:-:*:*:*:text-only:*:*:*

02 Apr 2026, 14:16

Type Values Removed Values Added
Summary
  • (es) Se encontró una falla en Keycloak. Un usuario autenticado con el rol view-users podría explotar una vulnerabilidad en el componente UserResource. Al acceder a un endpoint administrativo específico, este usuario podría recuperar indebidamente atributos de usuario que estaban configurados para estar ocultos. Esta revelación de información no autorizada podría exponer datos de usuario sensibles.
References
  • () https://access.redhat.com/errata/RHSA-2026:6477 -
  • () https://access.redhat.com/errata/RHSA-2026:6478 -

11 Mar 2026, 06:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-11 06:17

Updated : 2026-06-17 10:44


NVD link : CVE-2026-3911

Mitre link : CVE-2026-3911

CVE.ORG link : CVE-2026-3911


JSON object : View

Products Affected

redhat

  • build_of_keycloak
CWE
CWE-359

Exposure of Private Personal Information to an Unauthorized Actor

NVD-CWE-noinfo