A flaw was found in Keycloak. An administrator with `manage-users` permission can bypass the "Only administrators can view" setting for unmanaged attributes, allowing them to modify these attributes. This improper access control can lead to unauthorized changes to user profiles, even when the system is configured to restrict such modifications.
References
| Link | Resource |
|---|---|
| https://access.redhat.com/errata/RHSA-2026:2365 | Vendor Advisory |
| https://access.redhat.com/errata/RHSA-2026:2366 | Vendor Advisory |
| https://access.redhat.com/security/cve/CVE-2026-0871 | Vendor Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2428881 | Issue Tracking Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
05 Mar 2026, 02:03
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:redhat:build_of_keycloak:-:*:*:*:text-only:*:*:* cpe:2.3:a:redhat:keycloak:*:*:*:*:*:*:*:* cpe:2.3:a:redhat:build_of_keycloak:*:*:*:*:*:*:*:* |
|
| References | () https://access.redhat.com/errata/RHSA-2026:2365 - Vendor Advisory | |
| References | () https://access.redhat.com/errata/RHSA-2026:2366 - Vendor Advisory | |
| References | () https://access.redhat.com/security/cve/CVE-2026-0871 - Vendor Advisory | |
| References | () https://bugzilla.redhat.com/show_bug.cgi?id=2428881 - Issue Tracking, Vendor Advisory | |
| First Time |
Redhat
Redhat keycloak Redhat build Of Keycloak |
|
| CWE | NVD-CWE-noinfo |
27 Feb 2026, 08:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-27 08:17
Updated : 2026-03-05 02:03
NVD link : CVE-2026-0871
Mitre link : CVE-2026-0871
CVE.ORG link : CVE-2026-0871
JSON object : View
Products Affected
redhat
- keycloak
- build_of_keycloak
CWE
