CVE-2026-3911
LOWKeycloak - Info Disclosure
Title source: llmDescription
A flaw was found in Keycloak. An authenticated user with the view-users role could exploit a vulnerability in the UserResource component. By accessing a specific administrative endpoint, this user could improperly retrieve user attributes that were configured to be hidden. This unauthorized information disclosure could expose sensitive user data.
Scores
CVSS v3
2.7
EPSS
0.0001
EPSS Percentile
1.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
Details
CWE
CWE-359
Status
published
Products (1)
org.keycloak/keycloak-services
0Maven
Published
Mar 11, 2026
Tracked Since
Mar 11, 2026