PatchSiren cyber security CVE debrief
CVE-2026-3429 Red Hat CVE debrief
A flaw was identified in the Account REST API of Keycloak that allows a user authenticated at a lower security level to perform sensitive actions intended only for higher-assurance sessions. Specifically, an attacker who has already obtained a victim’s password can delete the victim’s registered MFA/OTP credential without first proving possession of that factor. The attacker can then register their own MFA device, effectively taking full control of the account. This weakness undermines the intended protection provided by multi-factor authentication. The CVE record was published on 2026-03-11T17:16:59.270Z and has not been modified since then. To address this vulnerability, defenders should verify the integrity of their Keycloak instances, review authentication and authorization configurations, and ensure that all necessary patches or updates are applied. Additionally, defenders should monitor for suspicious activity related to account management and MFA/OTP credentials. Evidence is based on official records from NVD and vendor advisories.
- Vendor
- Red Hat
- Product
- Red Hat build of Keycloak 26.4
- CVSS
- MEDIUM 4.2
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-03-11
- Original CVE updated
- 2026-08-18
- Advisory published
- 2026-03-11
- Advisory updated
- 2026-08-18
Who should care
Administrators and users of Keycloak instances, particularly those with multi-factor authentication enabled, should be aware of this vulnerability and take necessary defensive actions. This includes reviewing and updating Keycloak configurations, monitoring for suspicious activity, and applying vendor patches or updates. Additionally, security teams and vulnerability management teams should prioritize this vulnerability and ensure that all necessary mitigations are in place.
Technical summary
A flaw in the Account REST API of Keycloak allows a user authenticated at a lower security level to perform sensitive actions intended only for higher-assurance sessions. An attacker who has obtained a victim's password can delete the victim's registered MFA/OTP credential and register their own MFA device, effectively taking full control of the account. This vulnerability allows for lateral movement and escalation of privileges, undermining the security provided by multi-factor authentication. Defenders should prioritize patching or mitigating this vulnerability to prevent potential attacks.
Defensive priority
Medium-priority defensive actions are required to address this vulnerability, as it allows for lateral movement and escalation of privileges.
Recommended defensive actions
- Apply vendor patches or updates to address the vulnerability
- Review and update Keycloak configurations to ensure secure authentication and authorization
- Monitor for suspicious activity related to account management and MFA/OTP credentials
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and NVD entry provide details on the vulnerability in the Account REST API of Keycloak. Evidence is based on official records from NVD and vendor advisories. The vulnerability allows an attacker who has obtained a victim's password to delete the victim's registered MFA/OTP credential and register their own MFA device, effectively taking full control of the account. Defenders should verify the integrity of their Keycloak instances, review authentication and authorization configurations, and ensure that all necessary patches or updates are applied. Additionally, defenders should monitor for suspicious activity related to account management and MFA/OTP credentials.
Official resources
-
CVE-2026-3429 CVE record
CVE.org
-
CVE-2026-3429 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
-
Mitigation or vendor reference
[email protected] - Issue Tracking, Vendor Advisory
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-03-11T17:16:59.270Z and has not been modified since then.