A flaw was found in Keycloak. The org.keycloak.authorization package may be vulnerable to circumventing required actions, allowing users to circumvent requirements such as setting up two-factor authentication.
{ "versions": [ { "introduced": "26.0" }, { "fixed": "26.0.11" } ] }
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-3910.json"