Description

A flaw was found in Keycloak. The User-Managed Access (UMA) 2.0 Protection API endpoint for permission tickets fails to enforce the `uma_protection` role check. This allows any authenticated user with a token issued for a resource server client, even without the `uma_protection` role, to enumerate all permission tickets in the system. This vulnerability partial leads to information disclosure.

INFO

Published Date :

2026-03-26T19:12:38.438Z

Last Modified :

2026-04-02T16:39:39.516Z

Source :

redhat
AFFECTED PRODUCTS

The following products are affected by CVE-2026-3190 vulnerability.

Vendors Products
Keycloak
  • Keycloak
Redhat
  • Build Keycloak
  • Build Of Keycloak

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact