CVE-2026-0871

Severity
4.9MEDIUM
EPSS
0.0%
top 89.85%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 27

Description

A flaw was found in Keycloak. An administrator with `manage-users` permission can bypass the "Only administrators can view" setting for unmanaged attributes, allowing them to modify these attributes. This improper access control can lead to unauthorized changes to user profiles, even when the system is configured to restrict such modifications.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:NExploitability: 1.2 | Impact: 3.6

Affected Packages3 packages

🔴Vulnerability Details

3
OSV
Keycloak Server Private SPI: Improper Access Control Allows Administrators to Bypass Attribute Visibility Restrictions and Modify Unmanaged User Profile Attributes2026-02-27
CVEList
Org.keycloak/keycloak-services: keycloak: unauthorized modification of unmanaged user attributes by administrators2026-02-27
GHSA
Keycloak Server Private SPI: Improper Access Control Allows Administrators to Bypass Attribute Visibility Restrictions and Modify Unmanaged User Profile Attributes2026-02-27

📋Vendor Advisories

1
Red Hat
org.keycloak/keycloak-services: Keycloak: Unauthorized modification of unmanaged user attributes by administrators2025-01-13

🕵️Threat Intelligence

1
Wiz
CVE-2026-0871 Impact, Exploitability, and Mitigation Steps | Wiz

💬Community

1
Bugzilla
CVE-2026-0871 org.keycloak/keycloak-services: Keycloak: Unauthorized modification of unmanaged user attributes by administrators2026-01-13
CVE-2026-0871 (MEDIUM CVSS 4.9) | A flaw was found in Keycloak | cvebase.io