CVE-2025-3910: Red Hat Build Of Keycloak

Medium severity, CVSS 5.4. EPSS: 0.4% chance of exploitation in the next 30 days.

A flaw was found in Keycloak. The org.keycloak.authorization package may be vulnerable to circumventing required actions, allowing users to circumvent requirements such as setting up two-factor authentication.

Affected products

  • Red Hat Build Of Keycloak: from 26.0, before 26.0.11 (fixed in 26.0.11)

Published 2025-04-29. Last modified 2026-09-21.