Incorrect Privilege Assignment
CVE-2025-13881
Summary
A flaw was found in the Keycloak Admin API. This vulnerability allows an administrator with limited privileges to retrieve sensitive custom attributes via the "/unmanagedAttributes" endpoint, bypassing User Profile visibility settings. This issue affects versions 26.5.0 through 26.5.1 and versions prior to 26.4.9. It is patched in versions 26.5.2 and 26.4.9.
- LOW
- NETWORK
- NONE
- UNCHANGED
- NONE
- HIGH
- LOW
- NONE
CWE-266 - Incorrect Privilege Assignment
A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
References
Advisory Timeline
- Published