Логотип exploitDog
bind:CVE-2026-3911
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2026-3911

Количество 4

Количество 4

redhat логотип

CVE-2026-3911

16 дней назад

A flaw was found in Keycloak. An authenticated user with the view-users role could exploit a vulnerability in the UserResource component. By accessing a specific administrative endpoint, this user could improperly retrieve user attributes that were configured to be hidden. This unauthorized information disclosure could expose sensitive user data.

CVSS3: 2.7
EPSS: Низкий
nvd логотип

CVE-2026-3911

16 дней назад

A flaw was found in Keycloak. An authenticated user with the view-users role could exploit a vulnerability in the UserResource component. By accessing a specific administrative endpoint, this user could improperly retrieve user attributes that were configured to be hidden. This unauthorized information disclosure could expose sensitive user data.

CVSS3: 2.7
EPSS: Низкий
debian логотип

CVE-2026-3911

16 дней назад

A flaw was found in Keycloak. An authenticated user with the view-user ...

CVSS3: 2.7
EPSS: Низкий
github логотип

GHSA-xh32-c9wx-phrp

16 дней назад

Keycloak: Information disclosure of disabled user attributes via administrative endpoint

CVSS3: 2.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2026-3911

A flaw was found in Keycloak. An authenticated user with the view-users role could exploit a vulnerability in the UserResource component. By accessing a specific administrative endpoint, this user could improperly retrieve user attributes that were configured to be hidden. This unauthorized information disclosure could expose sensitive user data.

CVSS3: 2.7
0%
Низкий
16 дней назад
nvd логотип
CVE-2026-3911

A flaw was found in Keycloak. An authenticated user with the view-users role could exploit a vulnerability in the UserResource component. By accessing a specific administrative endpoint, this user could improperly retrieve user attributes that were configured to be hidden. This unauthorized information disclosure could expose sensitive user data.

CVSS3: 2.7
0%
Низкий
16 дней назад
debian логотип
CVE-2026-3911

A flaw was found in Keycloak. An authenticated user with the view-user ...

CVSS3: 2.7
0%
Низкий
16 дней назад
github логотип
GHSA-xh32-c9wx-phrp

Keycloak: Information disclosure of disabled user attributes via administrative endpoint

CVSS3: 2.7
0%
Низкий
16 дней назад

Уязвимостей на страницу