CVE-2026-3911

LOW

Keycloak - Info Disclosure

Title source: llm

Description

A flaw was found in Keycloak. An authenticated user with the view-users role could exploit a vulnerability in the UserResource component. By accessing a specific administrative endpoint, this user could improperly retrieve user attributes that were configured to be hidden. This unauthorized information disclosure could expose sensitive user data.

Scores

CVSS v3 2.7
EPSS 0.0001
EPSS Percentile 1.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-359
Status published
Products (1)
org.keycloak/keycloak-services 0Maven
Published Mar 11, 2026
Tracked Since Mar 11, 2026