BIT-keycloak-2026-3429

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/keycloak/BIT-keycloak-2026-3429.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-keycloak-2026-3429
Aliases
Published
2026-08-25T11:42:17Z
Modified
2026-09-08T08:48:06Z
Summary
Org.keycloak.services.resources.account: improper access control leading to mfa deletion and account takeover in keycloak account rest api
Details

A flaw was identified in the Account REST API of Keycloak that allows a user authenticated at a lower security level to perform sensitive actions intended only for higher-assurance sessions. Specifically, an attacker who has already obtained a victim’s password can delete the victim’s registered MFA/OTP credential without first proving possession of that factor. The attacker can then register their own MFA device, effectively taking full control of the account. This weakness undermines the intended protection provided by multi-factor authentication.

Database specific
{
    "cpes": [
        "cpe:2.3:a:redhat:build_of_keycloak:*:*:*:*:*:*:*:*",
        "cpe:2.3:a:keycloak:keycloak:*:*:*:*:*:*:*:*"
    ],
    "severity": "Medium"
}
References

Affected packages

Bitnami / keycloak

Package

Name
keycloak
Purl
pkg:bitnami/keycloak

Severity

  • 4.2 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
26.4.0
Fixed
26.4.11

Database specific

source
"https://github.com/bitnami/vulndb/tree/main/data/keycloak/BIT-keycloak-2026-3429.json"