Description

A flaw was found in Keycloak. An administrator with `manage-users` permission can bypass the "Only administrators can view" setting for unmanaged attributes, allowing them to modify these attributes. This improper access control can lead to unauthorized changes to user profiles, even when the system is configured to restrict such modifications.

INFO

Published Date :

2026-02-27T07:30:26.766Z

Last Modified :

2026-03-06T18:50:44.774Z

Source :

redhat
AFFECTED PRODUCTS

The following products are affected by CVE-2026-0871 vulnerability.

Vendors Products
Redhat
  • Build Keycloak
  • Build Of Keycloak
  • Jboss Enterprise Application Platform
  • Jboss Enterprise Application Platform Expansion Pack
  • Jbosseapxp
  • Keycloak
  • Red Hat Single Sign On

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact