CVE-2026-3429 identifies a medium-severity flaw in the Keycloak Account REST API. This vulnerability allows an attacker, who has already obtained a victim's password, to bypass multi-factor authentication by deleting the victim's registered MFA/OTP credential and subsequently registering their own, effectively taking full control of the account. The attack is network-based but requires high complexity due to the prerequisite of knowing the victim's password. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Red Hat | Red Hat Build Of Keycloak 26.4 | Range not provided by sourceCNA affecteddefault affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.