LIVE · cybersecurity feed
Live wire
cve recordmedium

CVE-2026-3429

redhat · build of keycloak

Published
CVSS4.2
Severitymedium
WeaknessCWE-284
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N

Description

A flaw was identified in the Account REST API of Keycloak that allows a user authenticated at a lower security level to perform sensitive actions intended only for higher-assurance sessions. Specifically, an attacker who has already obtained a victim’s password can delete the victim’s registered MFA/OTP credential without first proving possession of that factor. The attacker can then register their own MFA device, effectively taking full control of the account. This weakness undermines the intended protection provided by multi-factor authentication.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-3429

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-3429.