Improper access control in Keycloak - CVE-2025-14083
Published: September 10, 2026
Vulnerability identifier: #VU148934
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-14083
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to disclose backend schema and rules.
The vulnerability exists due to improper access control in the Keycloak Admin REST API when handling administrative API requests. A remote privileged user can access backend schema and rules to disclose backend schema and rules.
Affected software
Keycloak
Red Hat build of Keycloak
Red Hat build of Keycloak
How to mitigate CVE-2025-14083
Install security update from vendor's website.
Keycloak - addressed in versions 26.2.6, 26.5.7
Red Hat build of Keycloak - update to 26.4.11
Red Hat build of Keycloak - update to 26.4.11