« Volver al listado

CVE-2026-3911

Estado: AnalizadaBaja (2.7)—

A flaw was found in Keycloak. An authenticated user with the view-users role could exploit a vulnerability in the UserResource component. By accessing a specific administrative endpoint, this user could improperly retrieve user attributes that were configured to be hidden. This unauthorized information disclosure could expose sensitive user data.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-3911",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-3911",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-03-11T14:03:16.868337Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "secalert@redhat.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 2.7,
          "attackVector": "NETWORK",
          "baseSeverity": "LOW",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 1.2
      }
    ]
  },
  "affected": [
    {
      "source": "secalert@redhat.com",
      "affectedData": [
        {
          "cpes": [
            "cpe:/a:redhat:build_keycloak:26.4::el9"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat build of Keycloak 26.4",
          "versions": [
            {
              "status": "unaffected",
              "version": "26.4.11-1",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "rhbk/keycloak-operator-bundle",
          "collectionURL": "https://catalog.redhat.com/software/containers/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:build_keycloak:26.4::el9"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat build of Keycloak 26.4",
          "versions": [
            {
              "status": "unaffected",
              "version": "26.4-14",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "rhbk/keycloak-rhel9",
          "collectionURL": "https://catalog.redhat.com/software/containers/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:build_keycloak:26.4::el9"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat build of Keycloak 26.4",
          "versions": [
            {
              "status": "unaffected",
              "version": "26.4-14",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "rhbk/keycloak-rhel9-operator",
          "collectionURL": "https://catalog.redhat.com/software/containers/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:build_keycloak:26.4::el9"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat build of Keycloak 26.4.11",
          "packageName": "rhbk/keycloak-rhel9",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-03-11T06:17:15.377",
  "references": [
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:6477",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:6478",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://access.redhat.com/security/cve/CVE-2026-3911",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2446392",
      "tags": [
        "Issue Tracking"
      ],
      "source": "secalert@redhat.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "secalert@redhat.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-359"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A flaw was found in Keycloak. An authenticated user with the view-users role could exploit a vulnerability in the UserResource component. By accessing a specific administrative endpoint, this user could improperly retrieve user attributes that were configured to be hidden. This unauthorized information disclosure could expose sensitive user data."
    },
    {
      "lang": "es",
      "value": "Se encontró una falla en Keycloak. Un usuario autenticado con el rol view-users podría explotar una vulnerabilidad en el componente UserResource. Al acceder a un endpoint administrativo específico, este usuario podría recuperar indebidamente atributos de usuario que estaban configurados para estar ocultos. Esta revelación de información no autorizada podría exponer datos de usuario sensibles."
    }
  ],
  "lastModified": "2026-06-17T10:44:24.663",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:redhat:build_of_keycloak:-:*:*:*:text-only:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1830E455-7E11-4264-862D-05971A42D4A6"
            },
            {
              "criteria": "cpe:2.3:a:redhat:build_of_keycloak:26.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3C8F3485-92CB-4F23-A35A-AAA444FDF39E"
            },
            {
              "criteria": "cpe:2.3:a:redhat:build_of_keycloak:26.4.11:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F8B6CCB7-EDF2-41EA-A097-18340D5D03DE"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secalert@redhat.com"
}