PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-3429 Red Hat CVE debrief

A flaw was identified in the Account REST API of Keycloak that allows a user authenticated at a lower security level to perform sensitive actions intended only for higher-assurance sessions. Specifically, an attacker who has already obtained a victim’s password can delete the victim’s registered MFA/OTP credential without first proving possession of that factor. The attacker can then register their own MFA device, effectively taking full control of the account. This weakness undermines the intended protection provided by multi-factor authentication. The CVE record was published on 2026-03-11T17:16:59.270Z and has not been modified since then. To address this vulnerability, defenders should verify the integrity of their Keycloak instances, review authentication and authorization configurations, and ensure that all necessary patches or updates are applied. Additionally, defenders should monitor for suspicious activity related to account management and MFA/OTP credentials. Evidence is based on official records from NVD and vendor advisories.

Vendor
Red Hat
Product
Red Hat build of Keycloak 26.4
CVSS
MEDIUM 4.2
CISA KEV
Not listed in stored evidence
Original CVE published
2026-03-11
Original CVE updated
2026-08-18
Advisory published
2026-03-11
Advisory updated
2026-08-18

Who should care

Administrators and users of Keycloak instances, particularly those with multi-factor authentication enabled, should be aware of this vulnerability and take necessary defensive actions. This includes reviewing and updating Keycloak configurations, monitoring for suspicious activity, and applying vendor patches or updates. Additionally, security teams and vulnerability management teams should prioritize this vulnerability and ensure that all necessary mitigations are in place.

Technical summary

A flaw in the Account REST API of Keycloak allows a user authenticated at a lower security level to perform sensitive actions intended only for higher-assurance sessions. An attacker who has obtained a victim's password can delete the victim's registered MFA/OTP credential and register their own MFA device, effectively taking full control of the account. This vulnerability allows for lateral movement and escalation of privileges, undermining the security provided by multi-factor authentication. Defenders should prioritize patching or mitigating this vulnerability to prevent potential attacks.

Defensive priority

Medium-priority defensive actions are required to address this vulnerability, as it allows for lateral movement and escalation of privileges.

Recommended defensive actions

  • Apply vendor patches or updates to address the vulnerability
  • Review and update Keycloak configurations to ensure secure authentication and authorization
  • Monitor for suspicious activity related to account management and MFA/OTP credentials
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and NVD entry provide details on the vulnerability in the Account REST API of Keycloak. Evidence is based on official records from NVD and vendor advisories. The vulnerability allows an attacker who has obtained a victim's password to delete the victim's registered MFA/OTP credential and register their own MFA device, effectively taking full control of the account. Defenders should verify the integrity of their Keycloak instances, review authentication and authorization configurations, and ensure that all necessary patches or updates are applied. Additionally, defenders should monitor for suspicious activity related to account management and MFA/OTP credentials.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-03-11T17:16:59.270Z and has not been modified since then.