A flaw was found in Keycloak. The org.keycloak.authorization package may be vulnerable to circumventing required actions, allowing users to circumvent requirements such as setting up two-factor authentication.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-12659 A flaw was found in Keycloak. The org.keycloak.authorization package may be vulnerable to circumventing required actions, allowing users to circumvent requirements such as setting up two-factor authentication.
Github GHSA Github GHSA GHSA-5jfq-x6xp-7rw2 Keycloak vulnerable to two factor authentication bypass
Fixes

Solution

No solution given by the vendor.


Workaround

No current mitigations are available for this vulnerability.

History

Tue, 19 Aug 2025 01:00:00 +0900

Type Values Removed Values Added
First Time appeared Redhat build Of Keycloak
CPEs cpe:2.3:a:redhat:build_of_keycloak:*:*:*:*:text-only:*:*:*
Vendors & Products Redhat build Of Keycloak

Mon, 28 Jul 2025 22:00:00 +0900

Type Values Removed Values Added
References

Wed, 16 Jul 2025 22:45:00 +0900

Type Values Removed Values Added
Metrics epss

{'score': 0.00067}

epss

{'score': 0.00021}


Fri, 02 May 2025 11:45:00 +0900

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Thu, 01 May 2025 01:15:00 +0900

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 30 Apr 2025 11:30:00 +0900

Type Values Removed Values Added
CPEs cpe:/a:redhat:build_keycloak:26
References

Wed, 30 Apr 2025 08:15:00 +0900

Type Values Removed Values Added
CPEs cpe:/a:redhat:build_keycloak: cpe:/a:redhat:build_keycloak:26.0::el9
References

Wed, 30 Apr 2025 06:00:00 +0900

Type Values Removed Values Added
Description A flaw was found in Keycloak. The org.keycloak.authorization package may be vulnerable to circumventing required actions, allowing users to circumvent requirements such as setting up two-factor authentication.
Title Org.keycloak.authentication: two factor authentication bypass
First Time appeared Redhat
Redhat build Keycloak
Weaknesses CWE-287
CPEs cpe:/a:redhat:build_keycloak:
Vendors & Products Redhat
Redhat build Keycloak
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2025-11-20T20:24:18.031Z

Reserved: 2025-04-23T19:29:10.054Z

Link: CVE-2025-3910

cve-icon Vulnrichment

Updated: 2025-04-30T15:53:28.872Z

cve-icon NVD

Status : Analyzed

Published: 2025-04-29T21:15:51.707

Modified: 2025-08-18T15:55:00.800

Link: CVE-2025-3910

cve-icon Redhat

Severity : Moderate

Publid Date: 2025-04-29T00:00:00Z

Links: CVE-2025-3910 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses