Incorrect Privilege Assignment in Red Hat build of Keycloak - CVE-2026-0871
Published: September 11, 2026
Vulnerability details
The vulnerability allows a remote user to modify unmanaged user attributes.
The vulnerability exists due to improper access control in Keycloak\'s unmanaged user attributes handling when managing user attributes. A remote privileged user can modify unmanaged user attributes despite the configured restriction to modify unmanaged user attributes.
Exploitation requires the realm to have unmanaged attributes configured as \"Only administrators can view\" and the administrator to possess the `manage-users` permission.