THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-3429 (MEDIUM 4.2) — A flaw was identified in the Account REST API of Keycloak that allows a user authenticated at a lower security level to perform sensitive actions intended only for higher-assurance sessions. Specifically, an attacker who has already obtained a victim’s password can delete the vic

[NVD] CVE-2026-3429 (MEDIUM 4.2) — A flaw was identified in the Account REST API of Keycloak that allows a user authenticated at a lower security level to perform sensitive actions intended only for higher-assurance sessions. Specifically, an attacker who has already obtained a victim’s password can delete the vic

lownvdPublished 2026-03-11

CVE-2026-3429 CVSS: 4.2 MEDIUM Published: 2026-03-11T17:16:59.270

A flaw was identified in the Account REST API of Keycloak that allows a user authenticated at a lower security level to perform sensitive actions intended only for higher-assurance sessions. Specifically, an attacker who has already obtained a victim’s password can delete the victim’s registered MFA/OTP credential without first pro

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-3429