CVE-2026-3911 - Org.keycloak.services.resources.admin.userresource: keycloak: information disclosure of disabled user attributes via administrative endpoint
CVE ID :CVE-2026-3911
Published : March 11, 2026, 6:17 a.m. | 3 hours, 11 minutes ago
Description :A flaw was found in Keycloak. An authenticated user with the view-users role could exploit a vulnerability in the UserResource component. By accessing a specific administrative endpoint, this user could improperly retrieve user attributes that were configured to be hidden. This unauthorized information disclosure could expose sensitive user data.
Severity: 2.7 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : March 11, 2026, 6:17 a.m. | 3 hours, 11 minutes ago
Description :A flaw was found in Keycloak. An authenticated user with the view-users role could exploit a vulnerability in the UserResource component. By accessing a specific administrative endpoint, this user could improperly retrieve user attributes that were configured to be hidden. This unauthorized information disclosure could expose sensitive user data.
Severity: 2.7 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...