Access Control Flaw in Keycloak Affects User-Managed Access API
CVE-2026-3190

4.3MEDIUM

What is CVE-2026-3190?

A vulnerability in Keycloak's User-Managed Access (UMA) 2.0 Protection API allows authenticated users to bypass the uma_protection role check. This oversight permits any user with a valid token for a resource server client to enumerate all permission tickets stored in the system, potentially leading to unauthorized information disclosure. Security measures should be implemented to restrict access to the permission ticket endpoint.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Red Hat build of Keycloak 26.4 26.4.11-1

Red Hat build of Keycloak 26.4 26.4-14

Red Hat build of Keycloak 26.4 26.4-14

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Evan Hendra (Independent Security Researcher) for reporting this issue.
.