CVE-2026-3429 — A flaw was identified in the Account REST API of Keycloak that allows a user authenticated at a lower security level to perform sensitive actions intended only for higher-assurance sessions. Specifica — CVE Database · The Intelligence Room