Improper access control in Keycloak - CVE-2025-1391
Published: March 11, 2025
Vulnerability details
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper mapping of users to organizations based solely on email/username patterns. A remote attacker can trick an organization administrator into allowing user access based on naming pattern if, for example, self-registration is enabled and unrestricted.
Affected software
Red Hat build of Keycloak
How to mitigate CVE-2025-1391
Red Hat build of Keycloak - update to 26.0.10