Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 4

Количество 4

redhat логотип

CVE-2026-3190

6 месяцев назад

A flaw was found in Keycloak. The User-Managed Access (UMA) 2.0 Protection API endpoint for permission tickets fails to enforce the `uma_protection` role check. This allows any authenticated user with a token issued for a resource server client, even without the `uma_protection` role, to enumerate all permission tickets in the system. This vulnerability partial leads to information disclosure.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2026-3190

5 месяцев назад

A flaw was found in Keycloak. The User-Managed Access (UMA) 2.0 Protection API endpoint for permission tickets fails to enforce the `uma_protection` role check. This allows any authenticated user with a token issued for a resource server client, even without the `uma_protection` role, to enumerate all permission tickets in the system. This vulnerability partial leads to information disclosure.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2026-3190

5 месяцев назад

A flaw was found in Keycloak. The User-Managed Access (UMA) 2.0 Protec ...

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-q35r-vvhv-vx5h

5 месяцев назад

Keycloak: Missing Role Enforcement on UMA 2.0 Permission Ticket Endpoint Leads to Information Disclosure

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2026-3190

A flaw was found in Keycloak. The User-Managed Access (UMA) 2.0 Protection API endpoint for permission tickets fails to enforce the `uma_protection` role check. This allows any authenticated user with a token issued for a resource server client, even without the `uma_protection` role, to enumerate all permission tickets in the system. This vulnerability partial leads to information disclosure.

CVSS3: 4.3
0%
Низкий
6 месяцев назад
nvd логотип
CVE-2026-3190

A flaw was found in Keycloak. The User-Managed Access (UMA) 2.0 Protection API endpoint for permission tickets fails to enforce the `uma_protection` role check. This allows any authenticated user with a token issued for a resource server client, even without the `uma_protection` role, to enumerate all permission tickets in the system. This vulnerability partial leads to information disclosure.

CVSS3: 4.3
0%
Низкий
5 месяцев назад
debian логотип
CVE-2026-3190

A flaw was found in Keycloak. The User-Managed Access (UMA) 2.0 Protec ...

CVSS3: 4.3
0%
Низкий
5 месяцев назад
github логотип
GHSA-q35r-vvhv-vx5h

Keycloak: Missing Role Enforcement on UMA 2.0 Permission Ticket Endpoint Leads to Information Disclosure

CVSS3: 4.3
0%
Низкий
5 месяцев назад

Уязвимостей на страницу