Description
A flaw was found in Keycloak Admin API. This vulnerability allows an administrator with limited privileges to retrieve sensitive custom attributes via the /unmanagedAttributes endpoint, bypassing User Profile visibility settings.
Problem types
Incorrect Privilege Assignment
Product status
Timeline
| 2025-12-02: | Reported to Red Hat. |
| 2026-01-27: | Made public. |
Credits
Red Hat would like to thank Simone Paganessi for reporting this issue.
References
access.redhat.com/security/cve/CVE-2025-13881
bugzilla.redhat.com/show_bug.cgi?id=2418330 (RHBZ#2418330)