ZeroHour

CVE-2026-0871

CVSS 3.1
4.9 medium
EPSS
<1%p23
Published
()
Modified
Description

A flaw was found in Keycloak. An administrator with `manage-users` permission can bypass the "Only administrators can view" setting for unmanaged attributes, allowing them to modify these attributes. This improper access control can lead to unauthorized changes to user profiles, even when the system is configured to restrict such modifications.

Vendors
redhat
Products
build of keycloak, keycloak
Weakness
CWE-266
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.