CVE-2026-3911 - Org.keycloak.services.resources.admin.userresource: keycloak: information disclos...

CVE-2026-3911 - Org.keycloak.services.resources.admin.userresource: keycloak: information disclos...

CVE ID :CVE-2026-3911 Published : March 11, 2026, 6:17 a.m. | 50 minutes ago Description :A flaw was found in Keycloak. An authenticated user with the view-users role could exploit a vulnerability in the UserResource component. By accessing a specific administrative endpoint, this user could improperly retrieve user attributes that were configured to be hidden. This unauthorized information disclosure could expose sensitive user data. Severity: 2.7 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
LOW
Published
March 11, 2026
Impact: information disclosure