CVE-2026-3911
ADVISORY - githubSummary
A flaw was found in Keycloak. An authenticated user with the view-users role could exploit a vulnerability in the UserResource component. By accessing a specific administrative endpoint, this user could improperly retrieve user attributes that were configured to be hidden. This unauthorized information disclosure could expose sensitive user data.
EPSS Score: 0.00025 (0.066)
Common Weakness Enumeration (CWE)
ADVISORY - nist
Exposure of Private Personal Information to an Unauthorized Actor
ADVISORY - github
Exposure of Private Personal Information to an Unauthorized Actor
NIST
CREATED
UPDATED
ADVISORY IDCVE-2026-3911
EXPLOITABILITY SCORE
1.2
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)
CVSS SCORE
2.7lowGitHub
CREATED
UPDATED
ADVISORY IDGHSA-xh32-c9wx-phrp
EXPLOITABILITY SCORE
1.2
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)