Improper access control in Keycloak - CVE-2026-3429
Published: September 10, 2026
Vulnerability details
The vulnerability allows a remote user to take over an account.
The vulnerability exists due to improper access control in the Keycloak Account REST API when performing sensitive MFA credential actions from a lower-security session. A remote user can delete a victim\'s registered MFA/OTP credential and register an attacker-controlled MFA device to take over an account.
Exploitation requires possession of the victim\'s password.
Affected software
Red Hat build of Keycloak
How to mitigate CVE-2026-3429
Red Hat build of Keycloak - update to 26.4.11