VDB
CVE-2026-3429
CVE-2026-3429
PUBLISHED
CVSS 4.199999809265137 MEDIUM
A flaw was identified in the Account REST API of Keycloak that allows a user authenticated at a lower security level to perform sensitive actions intended only for higher-assurance sessions. Specifically, an attacker who has already obtained a victim’s password can delete the victim’s registered MFA/OTP credential without first proving possession of that factor. The attacker can then register their own MFA device, effectively taking full control of the account. This weakness undermines the intended protection provided by multi-factor authentication.
EPSS 0.02% · 4.2th percentile
Risk Scores
CVSS v3.1
4.199999809265137
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
EPSS Score
0.02%
4.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat Build of Keycloak | |
| Red Hat | Red Hat JBoss Enterprise Application Platform 8 | |
| Red Hat | Red Hat Single Sign-On 7 | |
| Red Hat | Red Hat build of Keycloak 26.4.11 | |
| Red Hat | Red Hat build of Keycloak 26.4 | 26.4.11-1 |
| Red Hat | Red Hat build of Keycloak 26.4 | 26.4-14 |
| Red Hat | Red Hat Build of Keycloak | |
| Maven | org.keycloak:keycloak-services | 0, 0 |
| Red Hat | Red Hat JBoss Enterprise Application Platform Expansion Pack | |
| Red Hat | Red Hat build of Keycloak 26.4 | 26.4-14 |
| Red Hat | Red Hat Build of Keycloak |
Timeline
- Mar 11, 2026 CVE Published
- Mar 12, 2026 EPSS Score
- Mar 13, 2026 EPSS Score
- Mar 14, 2026 EPSS Score
- Mar 15, 2026 EPSS Score
- Mar 16, 2026 EPSS Score
- Mar 17, 2026 EPSS Score
- Mar 17, 2026 Coalition ESS Score
- Mar 17, 2026 Security Advisory
- Mar 18, 2026 EPSS Score
- Mar 19, 2026 EPSS Score
- Mar 20, 2026 EPSS Score
References
- https://access.redhat.com/security/cve/CVE-2026-3429 vdb
- RHBZ#2443771 issue
- https://nvd.nist.gov/vuln/detail/CVE-2026-3429 advisory
- https://github.com/keycloak/keycloak/issues/47069 url
- https://github.com/keycloak/keycloak/commit/68f5779230d08825e6a4b4e23471fade16434178 url
- https://github.com/keycloak/keycloak package
- RHSA-2026:6477 vendor-advisory
- RHSA-2026:6478 vendor-advisory