CVE-2026-3429Patch(redhat / build_of_keycloak)

LOWCVSS 4.2 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch redhat build_of_keycloak systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw was identified in the Account REST API of Keycloak that allows a user authenticated at a lower security level to perform sensitive actions intended only for higher-assurance sessions. Specifically, an attacker who has already obtained a victim’s password can delete the victim’s registered MFA/OTP credential without first proving possession of that factor. The attacker can then register their own MFA device, effectively taking full control of the account. This weakness undermines the intended protection provided by multi-factor authentication.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • build_of_keycloak

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-04-07); latest day: 1
  • 5 total mentions across 4 days

Affected systems

Vendors
Products
build_of_keycloak

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-03-15: 1Mentions · 2026-04-06: 1Mentions · 2026-04-07: 2Mentions · 2026-04-20: 1Patch / Workaround · 2026-04-06: 1Patch / Workaround · 2026-04-20: 1Technical Details · 2026-03-15: 1Technical Details · 2026-04-06: 1Technical Details · 2026-04-07: 1Technical Details · 2026-04-20: 103-1504-0604-0704-20
Signal classification3 categories
Patch
240.0%
General
240.0%
Disclosure
120.0%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-03-151
Disclosure1
2026-04-061
Patch1
2026-04-072
General2
2026-04-201
Patch1
Full discourse5 posts
  • hamayanhamayan@hamayanhamayan
    General

    最近、初めてCVEを取った。CVE-2026-3429(Keycloak), CVE-2026-28871(WebKit) https://t.co/6tDBLAt1Qa

    Post summary

    The post merely lists newly acquired CVE identifiers without providing any technical, exploit, or patch details.

    44012477.9K
    1.9K followersView on X
  • GMO Flatt Security株式会社@flatt_security
    Patch

    弊社エンジニアの報告した脆弱性が4件公開されました。アドバイザリを参照し最新版へのアップデート等の対策を行ってください。 セキュリティエンジニア @koketiki 報告 ① CVE-2026-39410(HonoにおけるCookie Prefix保護のバイパス) https://flatt.tech/cve/CVE-2026-39410 セキュリティエンジニア @k1rnt 報告 ② CVE-2026-33810(Goのcrypto/x509におけるDNS名制約検証の大文字・小文字不一致によるバイパス) https://flatt.tech/cve/CVE-2026-33810 コーポレートエンジニア @hamayanhamayan 報告 ③ CVE-2026-3429(Keycloakにおけるアクセス制御不備) https://flatt.tech/cve/CVE-2026-3429 ④ CVE-2026-28871(WebKitにおけるXSSに繋がりうるロジックの脆弱性) https://flatt.tech/cve/CVE-2026-28871

    Post summary

    The message announces four newly disclosed CVEs from internal engineers, provides advisory links, and urges users to update to the latest versions for remediation.

    08436810.8K
    5.6K followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    Keycloak 26.5.7 fixes critical flaws including MFA bypass (CVE-2026-3429) and UMA token theft. Protect your IAM infrastructure—upgrade to the latest version. #Keycloak #CyberSecurity #MFA #IAM #InfoSec #VulnerabilityUpdate #OpenSource https://securityonline.info/keycloak-security-update-26-5-7-mfa-bypass-fix/ https://t.co/tRTSjaIdaH

    Post summary

    The post announces that Keycloak 26.5.7 fixes critical issues including an MFA bypass (CVE‑2026‑3429) and recommends users upgrade, with no indication of PoC, exploitation, or false‑positive claims.

    012030112.3K
    12.3K followersView on X
  • Netlas.io@Netlas_io
    General

    CVE-2026-3429, CVE-2026-4636 and others in Keycloak Several vulnerabilities in Keycloak allow attackers to bypass MFA, steal access tokens, and access confidential user data. 👉 https://nt.ls/Ooqi1 (https://nt.ls/Ooqi1)

    Post summary

    The post reports Keycloak CVEs that can bypass MFA and steal tokens, but offers no PoC, exploit code, patch information, or evidence of active exploitation.

    04051652
    7.5K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3429 A flaw was identified in the Account REST API of Keycloak that allows a user authenticated at a lower security level to perform sensitive actions intended only for high… https://www.cve.org/CVERecord?id=CVE-2026-3429

    Post summary

    A vulnerability in Keycloak’s Account REST API allowing unauthorized privilege escalation was disclosed; the post provides no exploit or patch details.

    00000176
    56.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appredhatbuild_of_keycloak---

Explore more