CVE-2025-3910
EUVD-2025-1265929.04.2025, 21:15
A flaw was found in Keycloak. The org.keycloak.authorization package may be vulnerable to circumventing required actions, allowing users to circumvent requirements such as setting up two-factor authentication.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| redhat | build_of_keycloak | 26.0 ≤ 𝑥 < 26.0.11 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration