Incorrect Privilege Assignment in Red Hat build of Keycloak - CVE-2025-13881

 

Incorrect Privilege Assignment in Red Hat build of Keycloak - CVE-2025-13881

Published: September 11, 2026


Vulnerability identifier: #VU148971
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-13881
CWE-ID: CWE-266
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive user attributes.

The vulnerability exists due to improper privilege assignment in the Keycloak Admin API when accessing the /unmanagedAttributes endpoint. A remote privileged user can retrieve sensitive custom attributes to disclose sensitive user attributes.

The endpoint bypasses User Profile visibility settings.


Affected software

Red Hat build of Keycloak

How to mitigate CVE-2025-13881

Install security update from vendor's website.

Red Hat build of Keycloak - update to 26.4.9

External References

Related Security Bulletins