Incorrect Privilege Assignment in Red Hat build of Keycloak - CVE-2026-0871

 

Incorrect Privilege Assignment in Red Hat build of Keycloak - CVE-2026-0871

Published: September 11, 2026


Vulnerability identifier: #VU148972
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-0871
CWE-ID: CWE-266
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to modify unmanaged user attributes.

The vulnerability exists due to improper access control in Keycloak\'s unmanaged user attributes handling when managing user attributes. A remote privileged user can modify unmanaged user attributes despite the configured restriction to modify unmanaged user attributes.

Exploitation requires the realm to have unmanaged attributes configured as \"Only administrators can view\" and the administrator to possess the `manage-users` permission.


Affected software

Red Hat build of Keycloak

How to mitigate CVE-2026-0871

Install security update from vendor's website.

Red Hat build of Keycloak - update to 26.4.9

External References

Related Security Bulletins