Incorrect authorization in Keycloak - CVE-2026-3190
Published: September 10, 2026
Vulnerability details
The vulnerability allows a remote user to disclose permission ticket information.
The vulnerability exists due to improper role enforcement in the UMA 2.0 Protection API when handling requests using a token issued for a resource server client. A remote user can enumerate permission tickets to disclose permission ticket information.
The token does not need the uma_protection role.
Affected software
Red Hat build of Keycloak
How to mitigate CVE-2026-3190
Red Hat build of Keycloak - update to 26.4.11