Home

Description

A flaw was found in Keycloak. An authenticated user with the view-users role could exploit a vulnerability in the UserResource component. By accessing a specific administrative endpoint, this user could improperly retrieve user attributes that were configured to be hidden. This unauthorized information disclosure could expose sensitive user data.

PUBLISHED Reserved 2026-03-11 | Published 2026-03-11 | Updated 2026-03-11 | Assigner redhat




LOW: 2.7CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N

Problem types

Exposure of Private Personal Information to an Unauthorized Actor

Product status

Default status
affected

Timeline

2026-03-11:Reported to Red Hat.
2026-03-11:Made public.

Credits

Red Hat would like to thank drak3hft7 for reporting this issue.

References

access.redhat.com/security/cve/CVE-2026-3911 vdb-entry

bugzilla.redhat.com/show_bug.cgi?id=2446392 (RHBZ#2446392) issue-tracking

cve.org (CVE-2026-3911)

nvd.nist.gov (CVE-2026-3911)

Download JSON