Exposure of Private Information ('Privacy Violation') in Keycloak - CVE-2026-3911
Published: September 10, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive user information.
The vulnerability exists due to improper access control in the UserResource component when accessing a specific administrative endpoint. A remote privileged user can retrieve user attributes configured to be hidden to disclose sensitive user information.
The user must have the view-users role.
Affected software
Red Hat build of Keycloak
How to mitigate CVE-2026-3911
Red Hat build of Keycloak - update to 26.4.11