CVE-2026-3911

A flaw was found in Keycloak. An authenticated user with the view-users role could exploit a vulnerability in the UserResource component. By accessing a specific administrative endpoint, this user could improperly retrieve user attributes that were configured to be hidden. This unauthorized information disclosure could expose sensitive user data.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:redhat:build_of_keycloak:-:*:*:*:text-only:*:*:*
cpe:2.3:a:redhat:build_of_keycloak:26.4:*:*:*:*:*:*:*
cpe:2.3:a:redhat:build_of_keycloak:26.4.11:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-03-11 06:17

Updated : 2026-06-17 10:44


NVD link : CVE-2026-3911

Mitre link : CVE-2026-3911

CVE.ORG link : CVE-2026-3911


JSON object : View

Products Affected

redhat

  • build_of_keycloak
CWE
CWE-359

Exposure of Private Personal Information to an Unauthorized Actor

NVD-CWE-noinfo