{"id":"CVE-2026-3190","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-3190","summary":"A flaw was found in Keycloak. The User-Managed Access (UMA) 2.0 Protection API endpoint for permission tickets fails to enforce the `uma_protection` role check. This allows any authenticated…","details":"A flaw was found in Keycloak. The User-Managed Access (UMA) 2.0 Protection API endpoint for permission tickets fails to enforce the `uma_protection` role check. This allows any authenticated user with a token issued for a resource server client, even without the `uma_protection` role, to enumerate all permission tickets in the system. This vulnerability partial leads to information disclosure.","published":"2026-03-26T19:17:06.413","modified":"2026-06-17T10:43:10.997","cvss":{"score":4.3,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:6477"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:6478"},{"type":"ADVISORY","url":"https://access.redhat.com/security/cve/CVE-2026-3190"},{"type":"ADVISORY","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2442572"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-06-17T10:43:10.997"}}