CVE-2026-3911
CVE-2026-3911: 1 tracked advisory record across Red Hat. Compare vendor sources and published fix guidance.
Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.
Vendor advisory comparison
Red Hat
1 advisory- Advisory severityLow2.7
Low [CVE-2026-3911] org.keycloak.services.resources.admin.UserResource: Keycloak: Information disclosure of disabled user attributes via administrative endpoint
CVE-2026-3911Source published
org.keycloak.services.resources.admin.UserResource: Keycloak: Information disclosure of disabled user attributes via administrative endpoint. Red Hat rates this low (CVSS 2.7). Weakness: CWE-359. Affected package(s): rhbk/keycloak-operator-bundle:26.4.11, rhbk/keycloak-rhel9, rhbk/keycloak-rhel9-operator:26.4, rhbk/keycloak-rhel9:26.4. Resolved in Red Hat advisory RHSA-2026:6478 — update the affected packages (`sudo dnf update`).
- Related products — impact not confirmed
- rhbk/keycloak-operator-bundle:26.4.11
- rhbk/keycloak-rhel9-operator:26.4
- rhbk/keycloak-rhel9:26.4
- Red Hat Enterprise Linux
- Source-reported affected versions
- rhbk/keycloak-operator-bundle:26.4.11-1
- rhbk/keycloak-rhel9
- rhbk/keycloak-rhel9-operator:26.4-14
- rhbk/keycloak-rhel9:26.4-14
- Source-reported fixed versions
- RHSA-2026:6478
- Mitigation guidance
- Update the affected package(s) to the fixed version shipped in RHSA-2026:6478 (`sudo dnf update` / `yum update`).
Android app · Google Play
Monitor future Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.