CVE-2026-3429 Details
Description
A flaw was identified in the Account REST API of Keycloak that allows a user authenticated at a lower security level to perform sensitive actions intended only for higher-assurance sessions. Specifically, an attacker who has already obtained a victim’s password can delete the victim’s registered MFA/OTP credential without first proving possession of that factor. The attacker can then register their own MFA device, effectively taking full control of the account. This weakness undermines the intended protection provided by multi-factor authentication.
A vulnerability exists in the Account REST API of Keycloak, where improper access control allows users authenticated at a lower security level to perform actions reserved for higher-assurance sessions. An attacker with a victim's password can delete the victim's multi-factor authentication (MFA) credential without verifying possession of that factor. This enables the attacker to register their own MFA device, gaining full control of the account. The issue arises from insufficient validation of the authentication Level of Assurance (LoA), undermining the protection intended by MFA.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 12, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2026:6477 | [email protected] | Vendor Advisory |
| https://access.redhat.com/errata/RHSA-2026:6478 | [email protected] | Vendor Advisory |
| https://access.redhat.com/security/cve/CVE-2026-3429 | [email protected] | Vendor Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2443771 | [email protected] | Issue TrackingVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-284 | Improper Access Control | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| redhat build of keycloak | >= 26.4, < 26.4.11 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 18, 2026 | Initial Analysis | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 2, 2026 | CVE Modified | [email protected] |
| Mar 11, 2026 | New CVE Received | [email protected] |