BIT-keycloak-2026-0871

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/keycloak/BIT-keycloak-2026-0871.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-keycloak-2026-0871
Aliases
Published
2026-08-25T11:41:30.675Z
Modified
2026-08-26T11:15:07.886084296Z
Summary
Org.keycloak/keycloak-services: keycloak: unauthorized modification of unmanaged user attributes by administrators
Details

A flaw was found in Keycloak. An administrator with manage-users permission can bypass the "Only administrators can view" setting for unmanaged attributes, allowing them to modify these attributes. This improper access control can lead to unauthorized changes to user profiles, even when the system is configured to restrict such modifications.

Database specific
{
    "severity": "Medium",
    "cpes": [
        "cpe:2.3:a:redhat:build_of_keycloak:*:*:*:*:text-only:*:*:*",
        "cpe:2.3:a:redhat:build_of_keycloak:*:*:*:*:*:*:*:*",
        "cpe:2.3:a:keycloak:keycloak:*:*:*:*:*:*:*:*"
    ]
}
References

Affected packages

Bitnami / keycloak

Package

Name
keycloak
Purl
pkg:bitnami/keycloak

Severity

  • 4.9 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
26.4.9

Database specific

source
"https://github.com/bitnami/vulndb/tree/main/data/keycloak/BIT-keycloak-2026-0871.json"