Description
A flaw was found in Keycloak Admin API. This vulnerability allows an administrator with limited privileges to retrieve sensitive custom attributes via the /unmanagedAttributes endpoint, bypassing User Profile visibility settings.
Problem types
Incorrect Privilege Assignment
Product status
26.4.9-1 (rpm) before *
26.4-11 (rpm) before *
26.4-10 (rpm) before *
Timeline
| 2025-12-02: | Reported to Red Hat. |
| 2026-01-27: | Made public. |
Credits
Red Hat would like to thank Simone Paganessi for reporting this issue.
References
access.redhat.com/errata/RHSA-2026:2365 (RHSA-2026:2365)
access.redhat.com/errata/RHSA-2026:2366 (RHSA-2026:2366)
access.redhat.com/security/cve/CVE-2025-13881
bugzilla.redhat.com/show_bug.cgi?id=2418330 (RHBZ#2418330)