CVE-2025-3910: Org.keycloak.authentication: two factor authentication bypass
Description A flaw was found in Keycloak. The org.keycloak.authorization package may be vulnerable to circumventing required actions, allowing users to circumvent requirements such as setting up two-factor authentication.
Other sources
AIA (Application-initiated actions) could be used to circumvent required actions configured by an administrator to be performed by a user upon signing in. This could lead to the user circumventing requirements such as setting up 2FA.
- A user account that has been required by an administrator to perform a required action. - The same user passing in a URL parameter during the sign in process.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3910?
CVE-2025-3910 is considered a critical vulnerability due to its potential to allow unauthorized circumvention of required security actions.
How do I fix CVE-2025-3910?
To mitigate CVE-2025-3910, update your Keycloak installation to the latest version that addresses this vulnerability.
What systems are affected by CVE-2025-3910?
CVE-2025-3910 affects installations of Keycloak, particularly those using the org.keycloak.authorization package.
What are the implications of CVE-2025-3910?
The implications of CVE-2025-3910 include the potential for users to bypass critical security measures like two-factor authentication.
Is there a workaround for CVE-2025-3910?
Currently, the recommended approach for CVE-2025-3910 is to update to a patched version of Keycloak rather than using a workaround.