Description
A flaw was found in the Keycloak Admin REST API. This vulnerability allows the exposure of backend schema and rules, potentially leading to targeted attacks or privilege escalation via improper access control.
Problem types
Product status
Timeline
| 2025-12-05: | Reported to Red Hat. |
| 2025-12-05: | Made public. |
Credits
Red Hat would like to thank Muhammad Usman (HackerSSG) (securetackles) for reporting this issue.
References
access.redhat.com/security/cve/CVE-2025-14083
bugzilla.redhat.com/show_bug.cgi?id=2419086 (RHBZ#2419086)