A flaw was found in Keycloak. An authenticated user with the view-users role could exploit a vulnerability in the UserResource component. By accessing a specific administrative endpoint, this user could improperly retrieve user attributes that were configured to be hidden. This unauthorized information disclosure could expose sensitive user data.
References
| Link | Resource |
|---|---|
| https://access.redhat.com/errata/RHSA-2026:6477 | Vendor Advisory |
| https://access.redhat.com/errata/RHSA-2026:6478 | Vendor Advisory |
| https://access.redhat.com/security/cve/CVE-2026-3911 | Vendor Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2446392 | Issue Tracking |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2026-03-11 06:17
Updated : 2026-06-17 10:44
NVD link : CVE-2026-3911
Mitre link : CVE-2026-3911
CVE.ORG link : CVE-2026-3911
JSON object : View
Products Affected
redhat
- build_of_keycloak
CWE
