Incorrect Privilege Assignment in Red Hat build of Keycloak - CVE-2025-13881
Published: September 11, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive user attributes.
The vulnerability exists due to improper privilege assignment in the Keycloak Admin API when accessing the /unmanagedAttributes endpoint. A remote privileged user can retrieve sensitive custom attributes to disclose sensitive user attributes.
The endpoint bypasses User Profile visibility settings.