CVE-2026-3429Medium· 4.2▾ SunlitA flaw was identified in the Account REST API of Keycloak that allows a user authenticated at a lower security level to perform sensitive actions intended only for higher-assurance sessions. Specifically, an attacker who has already obta…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 23.1 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 18.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
A flaw was identified in the Account REST API of Keycloak that allows a user authenticated at a lower security level to perform sensitive actions intended only for higher-assurance sessions. Specifically, an attacker who has already obtained a victim’s password can delete the victim’s registered MFA/OTP credential without first proving possession of that factor. The attacker can then register their own MFA device, effectively taking full control of the account. This weakness undermines the intended protection provided by multi-factor authentication.
build_of_keycloak >= 26.4, < 26.4.11Upgrade past the affected range:
build_of_keycloak 26.4.11Connected by shared product, vendor, weakness, or advisory.
CVE-2026-2366Low· 3.1A flaw was found in Keycloak
CVE-2026-1609High· 8.1A flaw was found in Keycloak
CVE-2026-16102High· 8.1A flaw was found in the Dynamic Client Registration (DCR) component of Keycloak, an identity and access management solution
CVE-2026-16072Medium· 4.9A flaw was found in the organization management component of Keycloak
CVE-2025-3910Medium· 5.4A flaw was found in Keycloak
CVE-2026-17059Medium· 6.5A flaw was found in the role-users endpoint of the keycloak-services library, which is the core component of the Keycloak identity and access management solution