Improper access control in Keycloak - CVE-2021-4133
Published: December 22, 2021 / Updated: June 29, 2026
Vulnerability details
The vulnerability allows a remote user to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions within the administrative REST API. A remote user can bypass implemented security restrictions and create new default user accounts, even when new user registration is disabled.
Affected software
Red Hat Single Sign-On
Rational Test Automation Server
rh-sso7-keycloak (Red Hat package)
How to mitigate CVE-2021-4133
Red Hat Single Sign-On - addressed in versions 7.5.0, 7.5.1
Rational Test Automation Server - update to 10.5
rh-sso7-keycloak (Red Hat package) - update to 15.0.2-3.redhat_00002.1.el7sso