PT-2026-22311 · Red Hat · Keycloak

·

CVE-2026-0871

·

Published

2026-02-27

·

Updated

2026-08-25

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Keycloak (affected versions not specified)
Description An issue exists in Keycloak where an administrator possessing manage-users permission can circumvent the intended restriction of the "Only administrators can view" setting for unmanaged attributes. This bypass allows administrators to modify these attributes, potentially leading to unauthorized changes to user profiles despite system configurations designed to prevent such modifications. The issue involves improper access control.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

LPE

Improper Access Control

Incorrect Privilege Assignment

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-KEYCLOAK-2026-0871
CVE-2026-0871
ECHO-738B-62C7-508F
GHSA-V4JW-M6RM-399H

Affected Products

Keycloak