
CVE-2026-3190 A flaw was found in Keycloak. The User-Managed Access (UMA) 2.0 Protection API endpoint for permission tickets fails to enforce the `uma_protection` role check. This al… https://www.cve.org/CVERecord?id=CVE-2026-3190
Post summary
A new vulnerability in Keycloak’s UMA 2.0 Protection API bypasses required role checks, potentially allowing unauthorized permission ticket handling.
