CVE-2026-0871
Severity
4.9MEDIUM
EPSS
0.0%
top 89.85%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 27
Description
A flaw was found in Keycloak. An administrator with `manage-users` permission can bypass the "Only administrators can view" setting for unmanaged attributes, allowing them to modify these attributes. This improper access control can lead to unauthorized changes to user profiles, even when the system is configured to restrict such modifications.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:NExploitability: 1.2 | Impact: 3.6
Affected Packages3 packages
🔴Vulnerability Details
3OSV▶
Keycloak Server Private SPI: Improper Access Control Allows Administrators to Bypass Attribute Visibility Restrictions and Modify Unmanaged User Profile Attributes↗2026-02-27
CVEList▶
Org.keycloak/keycloak-services: keycloak: unauthorized modification of unmanaged user attributes by administrators↗2026-02-27
GHSA▶
Keycloak Server Private SPI: Improper Access Control Allows Administrators to Bypass Attribute Visibility Restrictions and Modify Unmanaged User Profile Attributes↗2026-02-27
📋Vendor Advisories
1Red Hat▶
org.keycloak/keycloak-services: Keycloak: Unauthorized modification of unmanaged user attributes by administrators↗2025-01-13
🕵️Threat Intelligence
1💬Community
1Bugzilla▶
CVE-2026-0871 org.keycloak/keycloak-services: Keycloak: Unauthorized modification of unmanaged user attributes by administrators↗2026-01-13