THREAT OPS › Threat News › [NVD] CVE-2026-3429 (MEDIUM 4.2) — A flaw was identified in the Account REST API of Keycloak that allows a user authenticated at a lower security level to perform sensitive actions intended only for higher-assurance sessions. Specifically, an attacker who has already obtained a victim’s password can delete the vic
[NVD] CVE-2026-3429 (MEDIUM 4.2) — A flaw was identified in the Account REST API of Keycloak that allows a user authenticated at a lower security level to perform sensitive actions intended only for higher-assurance sessions. Specifically, an attacker who has already obtained a victim’s password can delete the vic
CVE-2026-3429 CVSS: 4.2 MEDIUM Published: 2026-03-11T17:16:59.270
A flaw was identified in the Account REST API of Keycloak that allows a user authenticated at a lower security level to perform sensitive actions intended only for higher-assurance sessions. Specifically, an attacker who has already obtained a victim’s password can delete the victim’s registered MFA/OTP credential without first pro
MITRE ATT&CK techniques
- Multi-Factor AuthenticationT1556.006
Indicators of compromise
- CVE-2026-3429cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-3429