Skip to main content

Incorrect Privilege Assignment

CVE-2025-13881

Severity Low
Score 2.7/10

Summary

A flaw was found in the Keycloak Admin API. This vulnerability allows an administrator with limited privileges to retrieve sensitive custom attributes via the "/unmanagedAttributes" endpoint, bypassing User Profile visibility settings. This issue affects versions 26.5.0 through 26.5.1 and versions prior to 26.4.9. It is patched in versions 26.5.2 and 26.4.9.

  • LOW
  • NETWORK
  • NONE
  • UNCHANGED
  • NONE
  • HIGH
  • LOW
  • NONE

CWE-266 - Incorrect Privilege Assignment

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

Advisory Timeline

  • Published