Access Control Flaw in Keycloak Affects User-Managed Access API
CVE-2026-3190
Key Information:
- Vendor
Red Hat
- Vendor
- CVE Published:
- 26 March 2026
What is CVE-2026-3190?
A vulnerability in Keycloak's User-Managed Access (UMA) 2.0 Protection API allows authenticated users to bypass the uma_protection role check. This oversight permits any user with a valid token for a resource server client to enumerate all permission tickets stored in the system, potentially leading to unauthorized information disclosure. Security measures should be implemented to restrict access to the permission ticket endpoint.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Red Hat build of Keycloak 26.4 26.4.11-1
Red Hat build of Keycloak 26.4 26.4-14
Red Hat build of Keycloak 26.4 26.4-14
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved