Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-3911

Опубликовано: 11 мар. 2026
Источник: nvd
CVSS3: 2.7
EPSS Низкий

Описание

A flaw was found in Keycloak. An authenticated user with the view-users role could exploit a vulnerability in the UserResource component. By accessing a specific administrative endpoint, this user could improperly retrieve user attributes that were configured to be hidden. This unauthorized information disclosure could expose sensitive user data.

EPSS

Процентиль: 1%
0.00011
Низкий

2.7 Low

CVSS3

Дефекты

CWE-359

Связанные уязвимости

CVSS3: 2.7
redhat
16 дней назад

A flaw was found in Keycloak. An authenticated user with the view-users role could exploit a vulnerability in the UserResource component. By accessing a specific administrative endpoint, this user could improperly retrieve user attributes that were configured to be hidden. This unauthorized information disclosure could expose sensitive user data.

CVSS3: 2.7
debian
16 дней назад

A flaw was found in Keycloak. An authenticated user with the view-user ...

CVSS3: 2.7
github
16 дней назад

Keycloak: Information disclosure of disabled user attributes via administrative endpoint

EPSS

Процентиль: 1%
0.00011
Низкий

2.7 Low

CVSS3

Дефекты

CWE-359