A flaw was found in Keycloak. The org.keycloak.authorization package may be vulnerable to circumventing required actions, allowing users to circumvent requirements such as setting up two-factor authentication.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-12659 A flaw was found in Keycloak. The org.keycloak.authorization package may be vulnerable to circumventing required actions, allowing users to circumvent requirements such as setting up two-factor authentication.
Github GHSA Github GHSA GHSA-5jfq-x6xp-7rw2 Keycloak vulnerable to two factor authentication bypass
Fixes

Solution

No solution given by the vendor.


Workaround

No current mitigations are available for this vulnerability.

History

Mon, 18 Aug 2025 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Redhat build Of Keycloak
CPEs cpe:2.3:a:redhat:build_of_keycloak:*:*:*:*:text-only:*:*:*
Vendors & Products Redhat build Of Keycloak

Mon, 28 Jul 2025 13:00:00 +0000

Type Values Removed Values Added
References

Wed, 16 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00067}

epss

{'score': 0.00021}


Fri, 02 May 2025 02:45:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Wed, 30 Apr 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 30 Apr 2025 02:30:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:build_keycloak:26
References

Tue, 29 Apr 2025 23:15:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:build_keycloak: cpe:/a:redhat:build_keycloak:26.0::el9
References

Tue, 29 Apr 2025 21:00:00 +0000

Type Values Removed Values Added
Description A flaw was found in Keycloak. The org.keycloak.authorization package may be vulnerable to circumventing required actions, allowing users to circumvent requirements such as setting up two-factor authentication.
Title Org.keycloak.authentication: two factor authentication bypass
First Time appeared Redhat
Redhat build Keycloak
Weaknesses CWE-287
CPEs cpe:/a:redhat:build_keycloak:
Vendors & Products Redhat
Redhat build Keycloak
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2025-11-20T20:24:18.031Z

Reserved: 2025-04-23T19:29:10.054Z

Link: CVE-2025-3910

cve-icon Vulnrichment

Updated: 2025-04-30T15:53:28.872Z

cve-icon NVD

Status : Analyzed

Published: 2025-04-29T21:15:51.707

Modified: 2025-08-18T15:55:00.800

Link: CVE-2025-3910

cve-icon Redhat

Severity : Moderate

Publid Date: 2025-04-29T00:00:00Z

Links: CVE-2025-3910 - Bugzilla

cve-icon OpenCVE Enrichment

No data.