A flaw was found in Keycloak. An authenticated user with the view-users role could exploit a vulnerability in the UserResource component. By accessing a specific administrative endpoint, this user could improperly retrieve user attributes that were configured to be hidden. This unauthorized information disclosure could expose sensitive user data.
Metrics
Affected Vendors & Products
References
History
Wed, 11 Mar 2026 06:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in Keycloak. An authenticated user with the view-users role could exploit a vulnerability in the UserResource component. By accessing a specific administrative endpoint, this user could improperly retrieve user attributes that were configured to be hidden. This unauthorized information disclosure could expose sensitive user data. | |
| Title | Org.keycloak.services.resources.admin.userresource: keycloak: information disclosure of disabled user attributes via administrative endpoint | |
| First Time appeared |
Redhat
Redhat build Keycloak |
|
| Weaknesses | CWE-359 | |
| CPEs | cpe:/a:redhat:build_keycloak: | |
| Vendors & Products |
Redhat
Redhat build Keycloak |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-03-11T05:36:43.743Z
Reserved: 2026-03-11T03:32:12.979Z
Link: CVE-2026-3911
No data.
Status : Received
Published: 2026-03-11T06:17:15.377
Modified: 2026-03-11T06:17:15.377
Link: CVE-2026-3911
No data.
OpenCVE Enrichment
No data.