cbcvebase.
CVE-2026-3911
published 2026-03-11

CVE-2026-3911: A flaw was found in Keycloak. An authenticated user with the view-users role could exploit a vulnerability in the UserResource component. By accessing a…

low2.7CVSS 3.1
AVNACLPRHUINSUCLINAN
A flaw was found in Keycloak. An authenticated user with the view-users role could exploit a vulnerability in the UserResource component. By accessing a specific administrative endpoint, this user could improperly retrieve user attributes that were configured to be hidden. This unauthorized information disclosure could expose sensitive user data.

Affected

2 ranges
VendorProductVersion rangeFixed in
redhatbuild_of_keycloak
redhatbuild_of_keycloak