
最近、初めてCVEを取った。CVE-2026-3429(Keycloak), CVE-2026-28871(WebKit) https://t.co/6tDBLAt1Qa
Post summary
The post merely lists newly acquired CVE identifiers without providing any technical, exploit, or patch details.
Signal is active with 1 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
A flaw was identified in the Account REST API of Keycloak that allows a user authenticated at a lower security level to perform sensitive actions intended only for higher-assurance sessions. Specifically, an attacker who has already obtained a victim’s password can delete the victim’s registered MFA/OTP credential without first proving possession of that factor. The attacker can then register their own MFA device, effectively taking full control of the account. This weakness undermines the intended protection provided by multi-factor authentication.
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
AVAILABLE
Momentum
STABLE
If you run products in this scope, you should treat this CVE as relevant to your environment.
| Date | Total | Labels |
|---|
| 2026-03-15 | 1 | Disclosure1 |
| 2026-04-06 | 1 | Patch1 |
| 2026-04-07 | 2 | General2 |
| 2026-04-20 | 1 | Patch1 |

最近、初めてCVEを取った。CVE-2026-3429(Keycloak), CVE-2026-28871(WebKit) https://t.co/6tDBLAt1Qa
Post summary
The post merely lists newly acquired CVE identifiers without providing any technical, exploit, or patch details.

弊社エンジニアの報告した脆弱性が4件公開されました。アドバイザリを参照し最新版へのアップデート等の対策を行ってください。 セキュリティエンジニア @koketiki 報告 ① CVE-2026-39410(HonoにおけるCookie Prefix保護のバイパス) https://flatt.tech/cve/CVE-2026-39410 セキュリティエンジニア @k1rnt 報告 ② CVE-2026-33810(Goのcrypto/x509におけるDNS名制約検証の大文字・小文字不一致によるバイパス) https://flatt.tech/cve/CVE-2026-33810 コーポレートエンジニア @hamayanhamayan 報告 ③ CVE-2026-3429(Keycloakにおけるアクセス制御不備) https://flatt.tech/cve/CVE-2026-3429 ④ CVE-2026-28871(WebKitにおけるXSSに繋がりうるロジックの脆弱性) https://flatt.tech/cve/CVE-2026-28871
Post summary
The message announces four newly disclosed CVEs from internal engineers, provides advisory links, and urges users to update to the latest versions for remediation.

Keycloak 26.5.7 fixes critical flaws including MFA bypass (CVE-2026-3429) and UMA token theft. Protect your IAM infrastructure—upgrade to the latest version. #Keycloak #CyberSecurity #MFA #IAM #InfoSec #VulnerabilityUpdate #OpenSource https://securityonline.info/keycloak-security-update-26-5-7-mfa-bypass-fix/ https://t.co/tRTSjaIdaH
Post summary
The post announces that Keycloak 26.5.7 fixes critical issues including an MFA bypass (CVE‑2026‑3429) and recommends users upgrade, with no indication of PoC, exploitation, or false‑positive claims.

CVE-2026-3429, CVE-2026-4636 and others in Keycloak Several vulnerabilities in Keycloak allow attackers to bypass MFA, steal access tokens, and access confidential user data. 👉 https://nt.ls/Ooqi1 (https://nt.ls/Ooqi1)
Post summary
The post reports Keycloak CVEs that can bypass MFA and steal tokens, but offers no PoC, exploit code, patch information, or evidence of active exploitation.

CVE-2026-3429 A flaw was identified in the Account REST API of Keycloak that allows a user authenticated at a lower security level to perform sensitive actions intended only for high… https://www.cve.org/CVERecord?id=CVE-2026-3429
Post summary
A vulnerability in Keycloak’s Account REST API allowing unauthorized privilege escalation was disclosed; the post provides no exploit or patch details.
1 of 1 entries
| Part | Vendor | Product | Version | Target SW | Target HW |
|---|---|---|---|---|---|
| App | redhat | build_of_keycloak | - | - | - |