org.keycloak.authentication: Two factor authentication bypass

cve CVE-2025-3910 2 sources, 2 claims · Watch

Red Hat writes:
org.keycloak.authentication: Two factor authentication bypass the claim
Severity
MEDIUM NVD
moderate Red Hat
CVSS
5.4 NVD
5.4 Red Hat
Fixed in
26.0.11, 26.2.2 NVD
Vendor
Red Hat NVD
Product
Red Hat Build of Keycloak NVD
CWE
CWE-287 NVD
CWE-287 Red Hat

How far exploitation has got

  1. No public code known
  2. Proof of concept
  3. Proof of concept, verified
  4. A Metasploit module
  5. Exploited in the wild
  6. Used in ransomware campaigns

Timeline

2025-04-29first spoke of it: A flaw was found in Keycloak. The org.keycloak.authorization package may be vulnerable to circumventing required actions, allowing users to circumvent requirements such as setting up two-factor authentication.NVD
2025-04-29first spoke of it: org.keycloak.authentication: Two factor authentication bypassRed Hat

What it is to other things

affectsredhat/build_of_keycloak
NVD
made_byredhat
NVD

In words only, so not counted until a person confirms one:

made_byred_hat
NVD says “Red Hat”
affectsred_hat/red_hat_build_of_keycloak
NVD says “Red Hat · Red Hat Build of Keycloak”
Every value, with what each source said and its receipt
PropertySourceSaidMeans here
Automatable
automatable
NVDno
At least one of those steps needs a person.
receipt
Source
NVD
Its words
no
Read by
field:cve.metrics.ssvcV203[].ssvcData.options[].automatable
Said since
2026-10-06 11:54 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 11:54 UTCno
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "collectionURL": "https://www.keycloak.org/",
            "defaultStatus": "unaffected",
            "packageName": "keycloak",
            "versions": [
              {
                "lessThan": "25.*",
                "status": "affected",
                "version": "25.0.0",
                "versionType": "semver"
              },
              {
                "lessThan": "26.0.11",
                "status": "affected",
                "version": "26.0.0",
                "versionType": "semver"
              },
              {
                "lessThan": "26.1.*",
                "status": "unknown",
                "version": "26.1.0",
                "versionType": "semver"
              },
              {
                "lessThan": "26.2.2",
                "status": "affected",
                "version": "26.2.0",
                "versionType": "semver"
              }
            ]
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.0"
            ],
            "defaultStatus": "unaffected",
            "packageName": "org.keycloak.authentication",
            "product": "Red Hat Build of Keycloak",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://catalog.redhat.com/software/containers/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.0::el9"
            ],
            "defaultStatus": "affected",
            "packageName": "rhbk/keycloak-operator-bundle",
            "product": "Red Hat build of Keycloak 26.0",
            "vendor": "Red Hat",
            "versions": [
              {
                "lessThan": "*",
                "status": "unaffected",
                "version": "26.0.11-2",
                "versionType": "rpm"
              }
            ]
          },
          {
            "collectionURL": "https://catalog.redhat.com/software/containers/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.0::el9"
            ],
            "defaultStatus": "affected",
            "packageName": "rhbk/keycloak-rhel9",
            "product": "Red Hat build of Keycloak 26.0",
            "vendor": "Red Hat",
            "versions": [
              {
                "lessThan": "*",
                "status": "unaffected",
                "version": "26.0-12",
                "versionType": "rpm"
              }
            ]
          },
          {
            "collectionURL": "https://catalog.redhat.com/software/containers/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.0::el9"
            ],
            "defaultStatus": "affected",
            "packageName": "rhbk/keycloak-rhel9-operator",
            "product": "Red Hat build of Keycloak 26.0",
            "vendor": "Red Hat",
            "versions": [
              {
                "lessThan": "*",
                "status": "unaffected",
                "version": "26.0-13",
                "versionType": "rpm"
              }
            ]
          }
        ],
        "source": "secalert@redhat.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:redhat:build_of_keycloak:*:*:*:*:text-only:*:*:*",
                "matchCriteriaId": "800270D6-AAEC-40D5-B10C-D5B30DF1F51C",
                "versionEndExcluding": "26.0.11",
                "versionStartIncluding": "26.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A flaw was found in Keycloak. The org.keycloak.authorization package may be vulnerable to circumventing required actions, allowing users to circumvent requirements such as setting up two-factor authentication."
      },
      {
        "lang": "es",
        "value": "Se detectó una falla en Keycloak. El paquete org.keycloak.authorization podría ser vulnerable a eludir acciones obligatorias, lo que permite a los usuarios eludir requisitos como la configuración de la autenticación de dos factores."
      }
    ],
    "id": "CVE-2025-3910",
    "lastModified": "2026-09-21T06:17:00.497",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.4,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 2.5,
          "source": "secalert@redhat.com",
          "type": "Secondary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.4,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 2.5,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-3910",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-04-30T15:52:31.582697Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-04-29T21:15:51.707",
    "references": [
      {
        "source": "secalert@redhat.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://access.redhat.com/errata/RHSA-2025:4335"
      },
      {
        "source": "secalert@redhat.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://access.redhat.com/errata/RHSA-2025:4336"
      },
      {
        "source": "secalert@redhat.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://access.redhat.com/security/cve/CVE-2025-3910"
      },
      {
        "source": "secalert@redhat.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2361923"
      },
      {
        "source": "secalert@redhat.com",
        "tags": [
          "Issue Tracking"
        ],
        "url": "https://github.com/keycloak/keycloak/issues/39349"
      }
    ],
    "sourceIdentifier": "secalert@redhat.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-287"
          }
        ],
        "source": "secalert@redhat.com",
        "type": "Secondary"
      }
    ]
  }
}
—
CVSS
cvss
NVD5.4
receipt
Source
NVD
Its words
5.4
Read by
field:cve.metrics.cvssMetricV31[type=Primary].cvssData.baseScore || field:cve.metrics.cvssMetricV31[].cvssData.baseScore
Said since
2026-09-29 09:45 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "collectionURL": "https://www.keycloak.org/",
            "defaultStatus": "unaffected",
            "packageName": "keycloak",
            "versions": [
              {
                "lessThan": "25.*",
                "status": "affected",
                "version": "25.0.0",
                "versionType": "semver"
              },
              {
                "lessThan": "26.0.11",
                "status": "affected",
                "version": "26.0.0",
                "versionType": "semver"
              },
              {
                "lessThan": "26.1.*",
                "status": "unknown",
                "version": "26.1.0",
                "versionType": "semver"
              },
              {
                "lessThan": "26.2.2",
                "status": "affected",
                "version": "26.2.0",
                "versionType": "semver"
              }
            ]
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.0"
            ],
            "defaultStatus": "unaffected",
            "packageName": "org.keycloak.authentication",
            "product": "Red Hat Build of Keycloak",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://catalog.redhat.com/software/containers/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.0::el9"
            ],
            "defaultStatus": "affected",
            "packageName": "rhbk/keycloak-operator-bundle",
            "product": "Red Hat build of Keycloak 26.0",
            "vendor": "Red Hat",
            "versions": [
              {
                "lessThan": "*",
                "status": "unaffected",
                "version": "26.0.11-2",
                "versionType": "rpm"
              }
            ]
          },
          {
            "collectionURL": "https://catalog.redhat.com/software/containers/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.0::el9"
            ],
            "defaultStatus": "affected",
            "packageName": "rhbk/keycloak-rhel9",
            "product": "Red Hat build of Keycloak 26.0",
            "vendor": "Red Hat",
            "versions": [
              {
                "lessThan": "*",
                "status": "unaffected",
                "version": "26.0-12",
                "versionType": "rpm"
              }
            ]
          },
          {
            "collectionURL": "https://catalog.redhat.com/software/containers/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.0::el9"
            ],
            "defaultStatus": "affected",
            "packageName": "rhbk/keycloak-rhel9-operator",
            "product": "Red Hat build of Keycloak 26.0",
            "vendor": "Red Hat",
            "versions": [
              {
                "lessThan": "*",
                "status": "unaffected",
                "version": "26.0-13",
                "versionType": "rpm"
              }
            ]
          }
        ],
        "source": "secalert@redhat.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:redhat:build_of_keycloak:*:*:*:*:text-only:*:*:*",
                "matchCriteriaId": "800270D6-AAEC-40D5-B10C-D5B30DF1F51C",
                "versionEndExcluding": "26.0.11",
                "versionStartIncluding": "26.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A flaw was found in Keycloak. The org.keycloak.authorization package may be vulnerable to circumventing required actions, allowing users to circumvent requirements such as setting up two-factor authentication."
      },
      {
        "lang": "es",
        "value": "Se detectó una falla en Keycloak. El paquete org.keycloak.authorization podría ser vulnerable a eludir acciones obligatorias, lo que permite a los usuarios eludir requisitos como la configuración de la autenticación de dos factores."
      }
    ],
    "id": "CVE-2025-3910",
    "lastModified": "2026-09-21T06:17:00.497",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.4,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 2.5,
          "source": "secalert@redhat.com",
          "type": "Secondary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.4,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 2.5,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-3910",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-04-30T15:52:31.582697Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-04-29T21:15:51.707",
    "references": [
      {
        "source": "secalert@redhat.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://access.redhat.com/errata/RHSA-2025:4335"
      },
      {
        "source": "secalert@redhat.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://access.redhat.com/errata/RHSA-2025:4336"
      },
      {
        "source": "secalert@redhat.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://access.redhat.com/security/cve/CVE-2025-3910"
      },
      {
        "source": "secalert@redhat.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2361923"
      },
      {
        "source": "secalert@redhat.com",
        "tags": [
          "Issue Tracking"
        ],
        "url": "https://github.com/keycloak/keycloak/issues/39349"
      }
    ],
    "sourceIdentifier": "secalert@redhat.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-287"
          }
        ],
        "source": "secalert@redhat.com",
        "type": "Secondary"
      }
    ]
  }
}
—
CVSS
cvss
Red Hat5.4
receipt
Source
Red Hat
Its words
5.4
Read by
field:cvss3_score
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-06 13:02 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2025-3910",
  "CWE": "CWE-287",
  "advisories": [
    "RHSA-2025:4336",
    "RHSA-2025:4335"
  ],
  "affected_packages": [
    "org.keycloak.authentication",
    "rhbk/keycloak-operator-bundle:26.0.11-2",
    "rhbk/keycloak-rhel9:26.0-12",
    "rhbk/keycloak-rhel9-operator:26.0-13"
  ],
  "bugzilla": "2361923",
  "bugzilla_description": "org.keycloak.authentication: Two factor authentication bypass",
  "cvss3_score": "5.4",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2025-04-29T00:00:00Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2025-3910.json",
  "severity": "moderate"
}
—
CVSS vector
cvss_vector
NVDCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
receipt
Source
NVD
Its words
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Read by
field:cve.metrics.cvssMetricV31[type=Primary].cvssData.vectorString || field:cve.metrics.cvssMetricV31[].cvssData.vectorString
Said since
2026-10-06 11:54 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 11:54 UTCCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "collectionURL": "https://www.keycloak.org/",
            "defaultStatus": "unaffected",
            "packageName": "keycloak",
            "versions": [
              {
                "lessThan": "25.*",
                "status": "affected",
                "version": "25.0.0",
                "versionType": "semver"
              },
              {
                "lessThan": "26.0.11",
                "status": "affected",
                "version": "26.0.0",
                "versionType": "semver"
              },
              {
                "lessThan": "26.1.*",
                "status": "unknown",
                "version": "26.1.0",
                "versionType": "semver"
              },
              {
                "lessThan": "26.2.2",
                "status": "affected",
                "version": "26.2.0",
                "versionType": "semver"
              }
            ]
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.0"
            ],
            "defaultStatus": "unaffected",
            "packageName": "org.keycloak.authentication",
            "product": "Red Hat Build of Keycloak",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://catalog.redhat.com/software/containers/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.0::el9"
            ],
            "defaultStatus": "affected",
            "packageName": "rhbk/keycloak-operator-bundle",
            "product": "Red Hat build of Keycloak 26.0",
            "vendor": "Red Hat",
            "versions": [
              {
                "lessThan": "*",
                "status": "unaffected",
                "version": "26.0.11-2",
                "versionType": "rpm"
              }
            ]
          },
          {
            "collectionURL": "https://catalog.redhat.com/software/containers/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.0::el9"
            ],
            "defaultStatus": "affected",
            "packageName": "rhbk/keycloak-rhel9",
            "product": "Red Hat build of Keycloak 26.0",
            "vendor": "Red Hat",
            "versions": [
              {
                "lessThan": "*",
                "status": "unaffected",
                "version": "26.0-12",
                "versionType": "rpm"
              }
            ]
          },
          {
            "collectionURL": "https://catalog.redhat.com/software/containers/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.0::el9"
            ],
            "defaultStatus": "affected",
            "packageName": "rhbk/keycloak-rhel9-operator",
            "product": "Red Hat build of Keycloak 26.0",
            "vendor": "Red Hat",
            "versions": [
              {
                "lessThan": "*",
                "status": "unaffected",
                "version": "26.0-13",
                "versionType": "rpm"
              }
            ]
          }
        ],
        "source": "secalert@redhat.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:redhat:build_of_keycloak:*:*:*:*:text-only:*:*:*",
                "matchCriteriaId": "800270D6-AAEC-40D5-B10C-D5B30DF1F51C",
                "versionEndExcluding": "26.0.11",
                "versionStartIncluding": "26.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A flaw was found in Keycloak. The org.keycloak.authorization package may be vulnerable to circumventing required actions, allowing users to circumvent requirements such as setting up two-factor authentication."
      },
      {
        "lang": "es",
        "value": "Se detectó una falla en Keycloak. El paquete org.keycloak.authorization podría ser vulnerable a eludir acciones obligatorias, lo que permite a los usuarios eludir requisitos como la configuración de la autenticación de dos factores."
      }
    ],
    "id": "CVE-2025-3910",
    "lastModified": "2026-09-21T06:17:00.497",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.4,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 2.5,
          "source": "secalert@redhat.com",
          "type": "Secondary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.4,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 2.5,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-3910",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-04-30T15:52:31.582697Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-04-29T21:15:51.707",
    "references": [
      {
        "source": "secalert@redhat.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://access.redhat.com/errata/RHSA-2025:4335"
      },
      {
        "source": "secalert@redhat.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://access.redhat.com/errata/RHSA-2025:4336"
      },
      {
        "source": "secalert@redhat.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://access.redhat.com/security/cve/CVE-2025-3910"
      },
      {
        "source": "secalert@redhat.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2361923"
      },
      {
        "source": "secalert@redhat.com",
        "tags": [
          "Issue Tracking"
        ],
        "url": "https://github.com/keycloak/keycloak/issues/39349"
      }
    ],
    "sourceIdentifier": "secalert@redhat.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-287"
          }
        ],
        "source": "secalert@redhat.com",
        "type": "Secondary"
      }
    ]
  }
}
—
CVSS vector
cvss_vector
Red HatCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
receipt
Source
Red Hat
Its words
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Read by
field:cvss3_scoring_vector
Said since
2026-10-06 13:01 UTC
Last answered
2026-10-06 13:02 UTC
Original
open at the source
2026-10-06 13:01 UTCCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
2026-09-29 09:44 UTC—
What the source handed over
{
  "CVE": "CVE-2025-3910",
  "CWE": "CWE-287",
  "advisories": [
    "RHSA-2025:4336",
    "RHSA-2025:4335"
  ],
  "affected_packages": [
    "org.keycloak.authentication",
    "rhbk/keycloak-operator-bundle:26.0.11-2",
    "rhbk/keycloak-rhel9:26.0-12",
    "rhbk/keycloak-rhel9-operator:26.0-13"
  ],
  "bugzilla": "2361923",
  "bugzilla_description": "org.keycloak.authentication: Two factor authentication bypass",
  "cvss3_score": "5.4",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2025-04-29T00:00:00Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2025-3910.json",
  "severity": "moderate"
}
—
CWE
cwe
NVDCWE-287
receipt
Source
NVD
Its words
CWE-287
Read by
field:cve.weaknesses[].description[].value
Said since
2026-10-06 11:54 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 11:54 UTCCWE-287
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "collectionURL": "https://www.keycloak.org/",
            "defaultStatus": "unaffected",
            "packageName": "keycloak",
            "versions": [
              {
                "lessThan": "25.*",
                "status": "affected",
                "version": "25.0.0",
                "versionType": "semver"
              },
              {
                "lessThan": "26.0.11",
                "status": "affected",
                "version": "26.0.0",
                "versionType": "semver"
              },
              {
                "lessThan": "26.1.*",
                "status": "unknown",
                "version": "26.1.0",
                "versionType": "semver"
              },
              {
                "lessThan": "26.2.2",
                "status": "affected",
                "version": "26.2.0",
                "versionType": "semver"
              }
            ]
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.0"
            ],
            "defaultStatus": "unaffected",
            "packageName": "org.keycloak.authentication",
            "product": "Red Hat Build of Keycloak",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://catalog.redhat.com/software/containers/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.0::el9"
            ],
            "defaultStatus": "affected",
            "packageName": "rhbk/keycloak-operator-bundle",
            "product": "Red Hat build of Keycloak 26.0",
            "vendor": "Red Hat",
            "versions": [
              {
                "lessThan": "*",
                "status": "unaffected",
                "version": "26.0.11-2",
                "versionType": "rpm"
              }
            ]
          },
          {
            "collectionURL": "https://catalog.redhat.com/software/containers/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.0::el9"
            ],
            "defaultStatus": "affected",
            "packageName": "rhbk/keycloak-rhel9",
            "product": "Red Hat build of Keycloak 26.0",
            "vendor": "Red Hat",
            "versions": [
              {
                "lessThan": "*",
                "status": "unaffected",
                "version": "26.0-12",
                "versionType": "rpm"
              }
            ]
          },
          {
            "collectionURL": "https://catalog.redhat.com/software/containers/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.0::el9"
            ],
            "defaultStatus": "affected",
            "packageName": "rhbk/keycloak-rhel9-operator",
            "product": "Red Hat build of Keycloak 26.0",
            "vendor": "Red Hat",
            "versions": [
              {
                "lessThan": "*",
                "status": "unaffected",
                "version": "26.0-13",
                "versionType": "rpm"
              }
            ]
          }
        ],
        "source": "secalert@redhat.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:redhat:build_of_keycloak:*:*:*:*:text-only:*:*:*",
                "matchCriteriaId": "800270D6-AAEC-40D5-B10C-D5B30DF1F51C",
                "versionEndExcluding": "26.0.11",
                "versionStartIncluding": "26.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A flaw was found in Keycloak. The org.keycloak.authorization package may be vulnerable to circumventing required actions, allowing users to circumvent requirements such as setting up two-factor authentication."
      },
      {
        "lang": "es",
        "value": "Se detectó una falla en Keycloak. El paquete org.keycloak.authorization podría ser vulnerable a eludir acciones obligatorias, lo que permite a los usuarios eludir requisitos como la configuración de la autenticación de dos factores."
      }
    ],
    "id": "CVE-2025-3910",
    "lastModified": "2026-09-21T06:17:00.497",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.4,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 2.5,
          "source": "secalert@redhat.com",
          "type": "Secondary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.4,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 2.5,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-3910",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-04-30T15:52:31.582697Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-04-29T21:15:51.707",
    "references": [
      {
        "source": "secalert@redhat.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://access.redhat.com/errata/RHSA-2025:4335"
      },
      {
        "source": "secalert@redhat.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://access.redhat.com/errata/RHSA-2025:4336"
      },
      {
        "source": "secalert@redhat.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://access.redhat.com/security/cve/CVE-2025-3910"
      },
      {
        "source": "secalert@redhat.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2361923"
      },
      {
        "source": "secalert@redhat.com",
        "tags": [
          "Issue Tracking"
        ],
        "url": "https://github.com/keycloak/keycloak/issues/39349"
      }
    ],
    "sourceIdentifier": "secalert@redhat.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-287"
          }
        ],
        "source": "secalert@redhat.com",
        "type": "Secondary"
      }
    ]
  }
}
—
CWE
cwe
Red HatCWE-287
receipt
Source
Red Hat
Its words
CWE-287
Read by
field:CWE
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-06 13:02 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2025-3910",
  "CWE": "CWE-287",
  "advisories": [
    "RHSA-2025:4336",
    "RHSA-2025:4335"
  ],
  "affected_packages": [
    "org.keycloak.authentication",
    "rhbk/keycloak-operator-bundle:26.0.11-2",
    "rhbk/keycloak-rhel9:26.0-12",
    "rhbk/keycloak-rhel9-operator:26.0-13"
  ],
  "bugzilla": "2361923",
  "bugzilla_description": "org.keycloak.authentication: Two factor authentication bypass",
  "cvss3_score": "5.4",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2025-04-29T00:00:00Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2025-3910.json",
  "severity": "moderate"
}
—
Exploitation
exploitation
NVDnone
No evidence of exploitation, and no public proof of concept.
receipt
Source
NVD
Its words
none
Read by
field:cve.metrics.ssvcV203[].ssvcData.options[].exploitation
Said since
2026-10-06 11:54 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 11:54 UTCnone
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "collectionURL": "https://www.keycloak.org/",
            "defaultStatus": "unaffected",
            "packageName": "keycloak",
            "versions": [
              {
                "lessThan": "25.*",
                "status": "affected",
                "version": "25.0.0",
                "versionType": "semver"
              },
              {
                "lessThan": "26.0.11",
                "status": "affected",
                "version": "26.0.0",
                "versionType": "semver"
              },
              {
                "lessThan": "26.1.*",
                "status": "unknown",
                "version": "26.1.0",
                "versionType": "semver"
              },
              {
                "lessThan": "26.2.2",
                "status": "affected",
                "version": "26.2.0",
                "versionType": "semver"
              }
            ]
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.0"
            ],
            "defaultStatus": "unaffected",
            "packageName": "org.keycloak.authentication",
            "product": "Red Hat Build of Keycloak",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://catalog.redhat.com/software/containers/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.0::el9"
            ],
            "defaultStatus": "affected",
            "packageName": "rhbk/keycloak-operator-bundle",
            "product": "Red Hat build of Keycloak 26.0",
            "vendor": "Red Hat",
            "versions": [
              {
                "lessThan": "*",
                "status": "unaffected",
                "version": "26.0.11-2",
                "versionType": "rpm"
              }
            ]
          },
          {
            "collectionURL": "https://catalog.redhat.com/software/containers/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.0::el9"
            ],
            "defaultStatus": "affected",
            "packageName": "rhbk/keycloak-rhel9",
            "product": "Red Hat build of Keycloak 26.0",
            "vendor": "Red Hat",
            "versions": [
              {
                "lessThan": "*",
                "status": "unaffected",
                "version": "26.0-12",
                "versionType": "rpm"
              }
            ]
          },
          {
            "collectionURL": "https://catalog.redhat.com/software/containers/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.0::el9"
            ],
            "defaultStatus": "affected",
            "packageName": "rhbk/keycloak-rhel9-operator",
            "product": "Red Hat build of Keycloak 26.0",
            "vendor": "Red Hat",
            "versions": [
              {
                "lessThan": "*",
                "status": "unaffected",
                "version": "26.0-13",
                "versionType": "rpm"
              }
            ]
          }
        ],
        "source": "secalert@redhat.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:redhat:build_of_keycloak:*:*:*:*:text-only:*:*:*",
                "matchCriteriaId": "800270D6-AAEC-40D5-B10C-D5B30DF1F51C",
                "versionEndExcluding": "26.0.11",
                "versionStartIncluding": "26.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A flaw was found in Keycloak. The org.keycloak.authorization package may be vulnerable to circumventing required actions, allowing users to circumvent requirements such as setting up two-factor authentication."
      },
      {
        "lang": "es",
        "value": "Se detectó una falla en Keycloak. El paquete org.keycloak.authorization podría ser vulnerable a eludir acciones obligatorias, lo que permite a los usuarios eludir requisitos como la configuración de la autenticación de dos factores."
      }
    ],
    "id": "CVE-2025-3910",
    "lastModified": "2026-09-21T06:17:00.497",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.4,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 2.5,
          "source": "secalert@redhat.com",
          "type": "Secondary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.4,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 2.5,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-3910",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-04-30T15:52:31.582697Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-04-29T21:15:51.707",
    "references": [
      {
        "source": "secalert@redhat.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://access.redhat.com/errata/RHSA-2025:4335"
      },
      {
        "source": "secalert@redhat.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://access.redhat.com/errata/RHSA-2025:4336"
      },
      {
        "source": "secalert@redhat.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://access.redhat.com/security/cve/CVE-2025-3910"
      },
      {
        "source": "secalert@redhat.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2361923"
      },
      {
        "source": "secalert@redhat.com",
        "tags": [
          "Issue Tracking"
        ],
        "url": "https://github.com/keycloak/keycloak/issues/39349"
      }
    ],
    "sourceIdentifier": "secalert@redhat.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-287"
          }
        ],
        "source": "secalert@redhat.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Fixed in
fixed_in
NVD26.0.11, 26.2.2
receipt
Source
NVD
Its words
26.0.11, 26.2.2
Read by
field:cve.affected[].affectedData[].versions[status=affected].lessThan
Said since
2026-10-06 11:54 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 11:54 UTC26.0.11, 26.2.2
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "collectionURL": "https://www.keycloak.org/",
            "defaultStatus": "unaffected",
            "packageName": "keycloak",
            "versions": [
              {
                "lessThan": "25.*",
                "status": "affected",
                "version": "25.0.0",
                "versionType": "semver"
              },
              {
                "lessThan": "26.0.11",
                "status": "affected",
                "version": "26.0.0",
                "versionType": "semver"
              },
              {
                "lessThan": "26.1.*",
                "status": "unknown",
                "version": "26.1.0",
                "versionType": "semver"
              },
              {
                "lessThan": "26.2.2",
                "status": "affected",
                "version": "26.2.0",
                "versionType": "semver"
              }
            ]
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.0"
            ],
            "defaultStatus": "unaffected",
            "packageName": "org.keycloak.authentication",
            "product": "Red Hat Build of Keycloak",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://catalog.redhat.com/software/containers/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.0::el9"
            ],
            "defaultStatus": "affected",
            "packageName": "rhbk/keycloak-operator-bundle",
            "product": "Red Hat build of Keycloak 26.0",
            "vendor": "Red Hat",
            "versions": [
              {
                "lessThan": "*",
                "status": "unaffected",
                "version": "26.0.11-2",
                "versionType": "rpm"
              }
            ]
          },
          {
            "collectionURL": "https://catalog.redhat.com/software/containers/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.0::el9"
            ],
            "defaultStatus": "affected",
            "packageName": "rhbk/keycloak-rhel9",
            "product": "Red Hat build of Keycloak 26.0",
            "vendor": "Red Hat",
            "versions": [
              {
                "lessThan": "*",
                "status": "unaffected",
                "version": "26.0-12",
                "versionType": "rpm"
              }
            ]
          },
          {
            "collectionURL": "https://catalog.redhat.com/software/containers/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.0::el9"
            ],
            "defaultStatus": "affected",
            "packageName": "rhbk/keycloak-rhel9-operator",
            "product": "Red Hat build of Keycloak 26.0",
            "vendor": "Red Hat",
            "versions": [
              {
                "lessThan": "*",
                "status": "unaffected",
                "version": "26.0-13",
                "versionType": "rpm"
              }
            ]
          }
        ],
        "source": "secalert@redhat.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:redhat:build_of_keycloak:*:*:*:*:text-only:*:*:*",
                "matchCriteriaId": "800270D6-AAEC-40D5-B10C-D5B30DF1F51C",
                "versionEndExcluding": "26.0.11",
                "versionStartIncluding": "26.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A flaw was found in Keycloak. The org.keycloak.authorization package may be vulnerable to circumventing required actions, allowing users to circumvent requirements such as setting up two-factor authentication."
      },
      {
        "lang": "es",
        "value": "Se detectó una falla en Keycloak. El paquete org.keycloak.authorization podría ser vulnerable a eludir acciones obligatorias, lo que permite a los usuarios eludir requisitos como la configuración de la autenticación de dos factores."
      }
    ],
    "id": "CVE-2025-3910",
    "lastModified": "2026-09-21T06:17:00.497",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.4,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 2.5,
          "source": "secalert@redhat.com",
          "type": "Secondary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.4,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 2.5,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-3910",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-04-30T15:52:31.582697Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-04-29T21:15:51.707",
    "references": [
      {
        "source": "secalert@redhat.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://access.redhat.com/errata/RHSA-2025:4335"
      },
      {
        "source": "secalert@redhat.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://access.redhat.com/errata/RHSA-2025:4336"
      },
      {
        "source": "secalert@redhat.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://access.redhat.com/security/cve/CVE-2025-3910"
      },
      {
        "source": "secalert@redhat.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2361923"
      },
      {
        "source": "secalert@redhat.com",
        "tags": [
          "Issue Tracking"
        ],
        "url": "https://github.com/keycloak/keycloak/issues/39349"
      }
    ],
    "sourceIdentifier": "secalert@redhat.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-287"
          }
        ],
        "source": "secalert@redhat.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Packages
packages
Red Hatorg.keycloak.authentication, rhbk/keycloak-operator-bundle:26.0.11-2, rhbk/keycloak-rhel9:26.0-12, rhbk/keycloak-rhel9-operator:26.0-13
receipt
Source
Red Hat
Its words
org.keycloak.authentication, rhbk/keycloak-operator-bundle:26.0.11-2, rhbk/keycloak-rhel9:26.0-12, rhbk/keycloak-rhel9-operator:26.0-13
Read by
field:affected_packages[]
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-06 13:02 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2025-3910",
  "CWE": "CWE-287",
  "advisories": [
    "RHSA-2025:4336",
    "RHSA-2025:4335"
  ],
  "affected_packages": [
    "org.keycloak.authentication",
    "rhbk/keycloak-operator-bundle:26.0.11-2",
    "rhbk/keycloak-rhel9:26.0-12",
    "rhbk/keycloak-rhel9-operator:26.0-13"
  ],
  "bugzilla": "2361923",
  "bugzilla_description": "org.keycloak.authentication: Two factor authentication bypass",
  "cvss3_score": "5.4",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2025-04-29T00:00:00Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2025-3910.json",
  "severity": "moderate"
}
—
Product
product
NVDRed Hat Build of Keycloak
receipt
Source
NVD
Its words
Red Hat Build of Keycloak
Read by
field:cve.affected[].affectedData[].product
Said since
2026-09-29 17:49 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-09-29 17:49 UTCRed Hat Build of Keycloak
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "collectionURL": "https://www.keycloak.org/",
            "defaultStatus": "unaffected",
            "packageName": "keycloak",
            "versions": [
              {
                "lessThan": "25.*",
                "status": "affected",
                "version": "25.0.0",
                "versionType": "semver"
              },
              {
                "lessThan": "26.0.11",
                "status": "affected",
                "version": "26.0.0",
                "versionType": "semver"
              },
              {
                "lessThan": "26.1.*",
                "status": "unknown",
                "version": "26.1.0",
                "versionType": "semver"
              },
              {
                "lessThan": "26.2.2",
                "status": "affected",
                "version": "26.2.0",
                "versionType": "semver"
              }
            ]
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.0"
            ],
            "defaultStatus": "unaffected",
            "packageName": "org.keycloak.authentication",
            "product": "Red Hat Build of Keycloak",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://catalog.redhat.com/software/containers/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.0::el9"
            ],
            "defaultStatus": "affected",
            "packageName": "rhbk/keycloak-operator-bundle",
            "product": "Red Hat build of Keycloak 26.0",
            "vendor": "Red Hat",
            "versions": [
              {
                "lessThan": "*",
                "status": "unaffected",
                "version": "26.0.11-2",
                "versionType": "rpm"
              }
            ]
          },
          {
            "collectionURL": "https://catalog.redhat.com/software/containers/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.0::el9"
            ],
            "defaultStatus": "affected",
            "packageName": "rhbk/keycloak-rhel9",
            "product": "Red Hat build of Keycloak 26.0",
            "vendor": "Red Hat",
            "versions": [
              {
                "lessThan": "*",
                "status": "unaffected",
                "version": "26.0-12",
                "versionType": "rpm"
              }
            ]
          },
          {
            "collectionURL": "https://catalog.redhat.com/software/containers/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.0::el9"
            ],
            "defaultStatus": "affected",
            "packageName": "rhbk/keycloak-rhel9-operator",
            "product": "Red Hat build of Keycloak 26.0",
            "vendor": "Red Hat",
            "versions": [
              {
                "lessThan": "*",
                "status": "unaffected",
                "version": "26.0-13",
                "versionType": "rpm"
              }
            ]
          }
        ],
        "source": "secalert@redhat.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:redhat:build_of_keycloak:*:*:*:*:text-only:*:*:*",
                "matchCriteriaId": "800270D6-AAEC-40D5-B10C-D5B30DF1F51C",
                "versionEndExcluding": "26.0.11",
                "versionStartIncluding": "26.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A flaw was found in Keycloak. The org.keycloak.authorization package may be vulnerable to circumventing required actions, allowing users to circumvent requirements such as setting up two-factor authentication."
      },
      {
        "lang": "es",
        "value": "Se detectó una falla en Keycloak. El paquete org.keycloak.authorization podría ser vulnerable a eludir acciones obligatorias, lo que permite a los usuarios eludir requisitos como la configuración de la autenticación de dos factores."
      }
    ],
    "id": "CVE-2025-3910",
    "lastModified": "2026-09-21T06:17:00.497",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.4,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 2.5,
          "source": "secalert@redhat.com",
          "type": "Secondary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.4,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 2.5,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-3910",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-04-30T15:52:31.582697Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-04-29T21:15:51.707",
    "references": [
      {
        "source": "secalert@redhat.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://access.redhat.com/errata/RHSA-2025:4335"
      },
      {
        "source": "secalert@redhat.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://access.redhat.com/errata/RHSA-2025:4336"
      },
      {
        "source": "secalert@redhat.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://access.redhat.com/security/cve/CVE-2025-3910"
      },
      {
        "source": "secalert@redhat.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2361923"
      },
      {
        "source": "secalert@redhat.com",
        "tags": [
          "Issue Tracking"
        ],
        "url": "https://github.com/keycloak/keycloak/issues/39349"
      }
    ],
    "sourceIdentifier": "secalert@redhat.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-287"
          }
        ],
        "source": "secalert@redhat.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Severity
severity
NVDMEDIUM
From 4.0 to 6.9.
receipt
Source
NVD
Its words
MEDIUM
Read by
field:cve.metrics.cvssMetricV31[type=Primary].cvssData.baseSeverity || field:cve.metrics.cvssMetricV31[].cvssData.baseSeverity
Said since
2026-10-06 11:54 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 11:54 UTCMEDIUM
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "collectionURL": "https://www.keycloak.org/",
            "defaultStatus": "unaffected",
            "packageName": "keycloak",
            "versions": [
              {
                "lessThan": "25.*",
                "status": "affected",
                "version": "25.0.0",
                "versionType": "semver"
              },
              {
                "lessThan": "26.0.11",
                "status": "affected",
                "version": "26.0.0",
                "versionType": "semver"
              },
              {
                "lessThan": "26.1.*",
                "status": "unknown",
                "version": "26.1.0",
                "versionType": "semver"
              },
              {
                "lessThan": "26.2.2",
                "status": "affected",
                "version": "26.2.0",
                "versionType": "semver"
              }
            ]
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.0"
            ],
            "defaultStatus": "unaffected",
            "packageName": "org.keycloak.authentication",
            "product": "Red Hat Build of Keycloak",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://catalog.redhat.com/software/containers/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.0::el9"
            ],
            "defaultStatus": "affected",
            "packageName": "rhbk/keycloak-operator-bundle",
            "product": "Red Hat build of Keycloak 26.0",
            "vendor": "Red Hat",
            "versions": [
              {
                "lessThan": "*",
                "status": "unaffected",
                "version": "26.0.11-2",
                "versionType": "rpm"
              }
            ]
          },
          {
            "collectionURL": "https://catalog.redhat.com/software/containers/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.0::el9"
            ],
            "defaultStatus": "affected",
            "packageName": "rhbk/keycloak-rhel9",
            "product": "Red Hat build of Keycloak 26.0",
            "vendor": "Red Hat",
            "versions": [
              {
                "lessThan": "*",
                "status": "unaffected",
                "version": "26.0-12",
                "versionType": "rpm"
              }
            ]
          },
          {
            "collectionURL": "https://catalog.redhat.com/software/containers/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.0::el9"
            ],
            "defaultStatus": "affected",
            "packageName": "rhbk/keycloak-rhel9-operator",
            "product": "Red Hat build of Keycloak 26.0",
            "vendor": "Red Hat",
            "versions": [
              {
                "lessThan": "*",
                "status": "unaffected",
                "version": "26.0-13",
                "versionType": "rpm"
              }
            ]
          }
        ],
        "source": "secalert@redhat.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:redhat:build_of_keycloak:*:*:*:*:text-only:*:*:*",
                "matchCriteriaId": "800270D6-AAEC-40D5-B10C-D5B30DF1F51C",
                "versionEndExcluding": "26.0.11",
                "versionStartIncluding": "26.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A flaw was found in Keycloak. The org.keycloak.authorization package may be vulnerable to circumventing required actions, allowing users to circumvent requirements such as setting up two-factor authentication."
      },
      {
        "lang": "es",
        "value": "Se detectó una falla en Keycloak. El paquete org.keycloak.authorization podría ser vulnerable a eludir acciones obligatorias, lo que permite a los usuarios eludir requisitos como la configuración de la autenticación de dos factores."
      }
    ],
    "id": "CVE-2025-3910",
    "lastModified": "2026-09-21T06:17:00.497",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.4,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 2.5,
          "source": "secalert@redhat.com",
          "type": "Secondary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.4,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 2.5,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-3910",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-04-30T15:52:31.582697Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-04-29T21:15:51.707",
    "references": [
      {
        "source": "secalert@redhat.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://access.redhat.com/errata/RHSA-2025:4335"
      },
      {
        "source": "secalert@redhat.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://access.redhat.com/errata/RHSA-2025:4336"
      },
      {
        "source": "secalert@redhat.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://access.redhat.com/security/cve/CVE-2025-3910"
      },
      {
        "source": "secalert@redhat.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2361923"
      },
      {
        "source": "secalert@redhat.com",
        "tags": [
          "Issue Tracking"
        ],
        "url": "https://github.com/keycloak/keycloak/issues/39349"
      }
    ],
    "sourceIdentifier": "secalert@redhat.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-287"
          }
        ],
        "source": "secalert@redhat.com",
        "type": "Secondary"
      }
    ]
  }
}
medium
Severity
severity
Red Hatmoderate
A flaw that is harder to exploit, or whose impact is limited.
receipt
Source
Red Hat
Its words
moderate
Read by
field:severity
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-06 13:02 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2025-3910",
  "CWE": "CWE-287",
  "advisories": [
    "RHSA-2025:4336",
    "RHSA-2025:4335"
  ],
  "affected_packages": [
    "org.keycloak.authentication",
    "rhbk/keycloak-operator-bundle:26.0.11-2",
    "rhbk/keycloak-rhel9:26.0-12",
    "rhbk/keycloak-rhel9-operator:26.0-13"
  ],
  "bugzilla": "2361923",
  "bugzilla_description": "org.keycloak.authentication: Two factor authentication bypass",
  "cvss3_score": "5.4",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2025-04-29T00:00:00Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2025-3910.json",
  "severity": "moderate"
}
medium
Status
status
NVDAnalyzed
receipt
Source
NVD
Its words
Analyzed
Read by
field:cve.vulnStatus
Said since
2026-09-29 09:45 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "collectionURL": "https://www.keycloak.org/",
            "defaultStatus": "unaffected",
            "packageName": "keycloak",
            "versions": [
              {
                "lessThan": "25.*",
                "status": "affected",
                "version": "25.0.0",
                "versionType": "semver"
              },
              {
                "lessThan": "26.0.11",
                "status": "affected",
                "version": "26.0.0",
                "versionType": "semver"
              },
              {
                "lessThan": "26.1.*",
                "status": "unknown",
                "version": "26.1.0",
                "versionType": "semver"
              },
              {
                "lessThan": "26.2.2",
                "status": "affected",
                "version": "26.2.0",
                "versionType": "semver"
              }
            ]
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.0"
            ],
            "defaultStatus": "unaffected",
            "packageName": "org.keycloak.authentication",
            "product": "Red Hat Build of Keycloak",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://catalog.redhat.com/software/containers/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.0::el9"
            ],
            "defaultStatus": "affected",
            "packageName": "rhbk/keycloak-operator-bundle",
            "product": "Red Hat build of Keycloak 26.0",
            "vendor": "Red Hat",
            "versions": [
              {
                "lessThan": "*",
                "status": "unaffected",
                "version": "26.0.11-2",
                "versionType": "rpm"
              }
            ]
          },
          {
            "collectionURL": "https://catalog.redhat.com/software/containers/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.0::el9"
            ],
            "defaultStatus": "affected",
            "packageName": "rhbk/keycloak-rhel9",
            "product": "Red Hat build of Keycloak 26.0",
            "vendor": "Red Hat",
            "versions": [
              {
                "lessThan": "*",
                "status": "unaffected",
                "version": "26.0-12",
                "versionType": "rpm"
              }
            ]
          },
          {
            "collectionURL": "https://catalog.redhat.com/software/containers/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.0::el9"
            ],
            "defaultStatus": "affected",
            "packageName": "rhbk/keycloak-rhel9-operator",
            "product": "Red Hat build of Keycloak 26.0",
            "vendor": "Red Hat",
            "versions": [
              {
                "lessThan": "*",
                "status": "unaffected",
                "version": "26.0-13",
                "versionType": "rpm"
              }
            ]
          }
        ],
        "source": "secalert@redhat.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:redhat:build_of_keycloak:*:*:*:*:text-only:*:*:*",
                "matchCriteriaId": "800270D6-AAEC-40D5-B10C-D5B30DF1F51C",
                "versionEndExcluding": "26.0.11",
                "versionStartIncluding": "26.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A flaw was found in Keycloak. The org.keycloak.authorization package may be vulnerable to circumventing required actions, allowing users to circumvent requirements such as setting up two-factor authentication."
      },
      {
        "lang": "es",
        "value": "Se detectó una falla en Keycloak. El paquete org.keycloak.authorization podría ser vulnerable a eludir acciones obligatorias, lo que permite a los usuarios eludir requisitos como la configuración de la autenticación de dos factores."
      }
    ],
    "id": "CVE-2025-3910",
    "lastModified": "2026-09-21T06:17:00.497",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.4,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 2.5,
          "source": "secalert@redhat.com",
          "type": "Secondary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.4,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 2.5,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-3910",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-04-30T15:52:31.582697Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-04-29T21:15:51.707",
    "references": [
      {
        "source": "secalert@redhat.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://access.redhat.com/errata/RHSA-2025:4335"
      },
      {
        "source": "secalert@redhat.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://access.redhat.com/errata/RHSA-2025:4336"
      },
      {
        "source": "secalert@redhat.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://access.redhat.com/security/cve/CVE-2025-3910"
      },
      {
        "source": "secalert@redhat.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2361923"
      },
      {
        "source": "secalert@redhat.com",
        "tags": [
          "Issue Tracking"
        ],
        "url": "https://github.com/keycloak/keycloak/issues/39349"
      }
    ],
    "sourceIdentifier": "secalert@redhat.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-287"
          }
        ],
        "source": "secalert@redhat.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Technical impact
technical_impact
NVDpartial
The attacker gains limited control, or limited information.
receipt
Source
NVD
Its words
partial
Read by
field:cve.metrics.ssvcV203[].ssvcData.options[].technicalImpact
Said since
2026-10-06 11:54 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 11:54 UTCpartial
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "collectionURL": "https://www.keycloak.org/",
            "defaultStatus": "unaffected",
            "packageName": "keycloak",
            "versions": [
              {
                "lessThan": "25.*",
                "status": "affected",
                "version": "25.0.0",
                "versionType": "semver"
              },
              {
                "lessThan": "26.0.11",
                "status": "affected",
                "version": "26.0.0",
                "versionType": "semver"
              },
              {
                "lessThan": "26.1.*",
                "status": "unknown",
                "version": "26.1.0",
                "versionType": "semver"
              },
              {
                "lessThan": "26.2.2",
                "status": "affected",
                "version": "26.2.0",
                "versionType": "semver"
              }
            ]
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.0"
            ],
            "defaultStatus": "unaffected",
            "packageName": "org.keycloak.authentication",
            "product": "Red Hat Build of Keycloak",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://catalog.redhat.com/software/containers/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.0::el9"
            ],
            "defaultStatus": "affected",
            "packageName": "rhbk/keycloak-operator-bundle",
            "product": "Red Hat build of Keycloak 26.0",
            "vendor": "Red Hat",
            "versions": [
              {
                "lessThan": "*",
                "status": "unaffected",
                "version": "26.0.11-2",
                "versionType": "rpm"
              }
            ]
          },
          {
            "collectionURL": "https://catalog.redhat.com/software/containers/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.0::el9"
            ],
            "defaultStatus": "affected",
            "packageName": "rhbk/keycloak-rhel9",
            "product": "Red Hat build of Keycloak 26.0",
            "vendor": "Red Hat",
            "versions": [
              {
                "lessThan": "*",
                "status": "unaffected",
                "version": "26.0-12",
                "versionType": "rpm"
              }
            ]
          },
          {
            "collectionURL": "https://catalog.redhat.com/software/containers/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.0::el9"
            ],
            "defaultStatus": "affected",
            "packageName": "rhbk/keycloak-rhel9-operator",
            "product": "Red Hat build of Keycloak 26.0",
            "vendor": "Red Hat",
            "versions": [
              {
                "lessThan": "*",
                "status": "unaffected",
                "version": "26.0-13",
                "versionType": "rpm"
              }
            ]
          }
        ],
        "source": "secalert@redhat.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:redhat:build_of_keycloak:*:*:*:*:text-only:*:*:*",
                "matchCriteriaId": "800270D6-AAEC-40D5-B10C-D5B30DF1F51C",
                "versionEndExcluding": "26.0.11",
                "versionStartIncluding": "26.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A flaw was found in Keycloak. The org.keycloak.authorization package may be vulnerable to circumventing required actions, allowing users to circumvent requirements such as setting up two-factor authentication."
      },
      {
        "lang": "es",
        "value": "Se detectó una falla en Keycloak. El paquete org.keycloak.authorization podría ser vulnerable a eludir acciones obligatorias, lo que permite a los usuarios eludir requisitos como la configuración de la autenticación de dos factores."
      }
    ],
    "id": "CVE-2025-3910",
    "lastModified": "2026-09-21T06:17:00.497",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.4,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 2.5,
          "source": "secalert@redhat.com",
          "type": "Secondary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.4,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 2.5,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-3910",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-04-30T15:52:31.582697Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-04-29T21:15:51.707",
    "references": [
      {
        "source": "secalert@redhat.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://access.redhat.com/errata/RHSA-2025:4335"
      },
      {
        "source": "secalert@redhat.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://access.redhat.com/errata/RHSA-2025:4336"
      },
      {
        "source": "secalert@redhat.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://access.redhat.com/security/cve/CVE-2025-3910"
      },
      {
        "source": "secalert@redhat.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2361923"
      },
      {
        "source": "secalert@redhat.com",
        "tags": [
          "Issue Tracking"
        ],
        "url": "https://github.com/keycloak/keycloak/issues/39349"
      }
    ],
    "sourceIdentifier": "secalert@redhat.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-287"
          }
        ],
        "source": "secalert@redhat.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Vendor
vendor
NVDRed Hat
receipt
Source
NVD
Its words
Red Hat
Read by
field:cve.affected[].affectedData[].vendor
Said since
2026-09-29 17:49 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-09-29 17:49 UTCRed Hat
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "collectionURL": "https://www.keycloak.org/",
            "defaultStatus": "unaffected",
            "packageName": "keycloak",
            "versions": [
              {
                "lessThan": "25.*",
                "status": "affected",
                "version": "25.0.0",
                "versionType": "semver"
              },
              {
                "lessThan": "26.0.11",
                "status": "affected",
                "version": "26.0.0",
                "versionType": "semver"
              },
              {
                "lessThan": "26.1.*",
                "status": "unknown",
                "version": "26.1.0",
                "versionType": "semver"
              },
              {
                "lessThan": "26.2.2",
                "status": "affected",
                "version": "26.2.0",
                "versionType": "semver"
              }
            ]
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.0"
            ],
            "defaultStatus": "unaffected",
            "packageName": "org.keycloak.authentication",
            "product": "Red Hat Build of Keycloak",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://catalog.redhat.com/software/containers/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.0::el9"
            ],
            "defaultStatus": "affected",
            "packageName": "rhbk/keycloak-operator-bundle",
            "product": "Red Hat build of Keycloak 26.0",
            "vendor": "Red Hat",
            "versions": [
              {
                "lessThan": "*",
                "status": "unaffected",
                "version": "26.0.11-2",
                "versionType": "rpm"
              }
            ]
          },
          {
            "collectionURL": "https://catalog.redhat.com/software/containers/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.0::el9"
            ],
            "defaultStatus": "affected",
            "packageName": "rhbk/keycloak-rhel9",
            "product": "Red Hat build of Keycloak 26.0",
            "vendor": "Red Hat",
            "versions": [
              {
                "lessThan": "*",
                "status": "unaffected",
                "version": "26.0-12",
                "versionType": "rpm"
              }
            ]
          },
          {
            "collectionURL": "https://catalog.redhat.com/software/containers/",
            "cpes": [
              "cpe:/a:redhat:build_keycloak:26.0::el9"
            ],
            "defaultStatus": "affected",
            "packageName": "rhbk/keycloak-rhel9-operator",
            "product": "Red Hat build of Keycloak 26.0",
            "vendor": "Red Hat",
            "versions": [
              {
                "lessThan": "*",
                "status": "unaffected",
                "version": "26.0-13",
                "versionType": "rpm"
              }
            ]
          }
        ],
        "source": "secalert@redhat.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:redhat:build_of_keycloak:*:*:*:*:text-only:*:*:*",
                "matchCriteriaId": "800270D6-AAEC-40D5-B10C-D5B30DF1F51C",
                "versionEndExcluding": "26.0.11",
                "versionStartIncluding": "26.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A flaw was found in Keycloak. The org.keycloak.authorization package may be vulnerable to circumventing required actions, allowing users to circumvent requirements such as setting up two-factor authentication."
      },
      {
        "lang": "es",
        "value": "Se detectó una falla en Keycloak. El paquete org.keycloak.authorization podría ser vulnerable a eludir acciones obligatorias, lo que permite a los usuarios eludir requisitos como la configuración de la autenticación de dos factores."
      }
    ],
    "id": "CVE-2025-3910",
    "lastModified": "2026-09-21T06:17:00.497",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.4,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 2.5,
          "source": "secalert@redhat.com",
          "type": "Secondary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.4,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 2.5,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-3910",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-04-30T15:52:31.582697Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-04-29T21:15:51.707",
    "references": [
      {
        "source": "secalert@redhat.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://access.redhat.com/errata/RHSA-2025:4335"
      },
      {
        "source": "secalert@redhat.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://access.redhat.com/errata/RHSA-2025:4336"
      },
      {
        "source": "secalert@redhat.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://access.redhat.com/security/cve/CVE-2025-3910"
      },
      {
        "source": "secalert@redhat.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2361923"
      },
      {
        "source": "secalert@redhat.com",
        "tags": [
          "Issue Tracking"
        ],
        "url": "https://github.com/keycloak/keycloak/issues/39349"
      }
    ],
    "sourceIdentifier": "secalert@redhat.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-287"
          }
        ],
        "source": "secalert@redhat.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Every claim, by kind

vulnerability

org.keycloak.authentication: Two factor authentication bypass
zetlyn/cve-redhat · 2025-04-29
cvss 5.4 cvss_vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N cwe CWE-287 packages org.keycloak.authentication, rhbk/keycloak-operator-bundle:26.0.11-2, rhbk/keycloak-rhel9:26.0-12, rhbk/keycloak-rhel9-operator:26.0-13 severity moderate source
A flaw was found in Keycloak. The org.keycloak.authorization package may be vulnerable to circumventing required actions, allowing users to circumvent requirements such as setting up two-factor authentication.
zetlyn/cve-nvd · 2025-04-29
automatable no cvss 5.4 cvss_vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N cwe CWE-287 exploitation none fixed_in 26.0.11, 26.2.2 product Red Hat Build of Keycloak severity MEDIUM status Analyzed technical_impact partial vendor Red Hat source