CVE-2026-0871

Name
CVE-2026-0871
Description
A flaw was found in Keycloak. An administrator with `manage-users` permission can bypass the "Only administrators can view" setting for unmanaged attributes, allowing them to modify these attributes. This improper access control can lead to unauthorized changes to user profiles, even when the system is configured to restrict such modifications.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
secalert@redhat.com https://access.redhat.com/errata/RHSA-2026:2365
secalert@redhat.com https://access.redhat.com/errata/RHSA-2026:2366
secalert@redhat.com https://access.redhat.com/security/cve/CVE-2026-0871
secalert@redhat.com https://bugzilla.redhat.com/show_bug.cgi?id=2428881

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:redhat:build_of_keycloak:*:*:*:*:*:*:*:* build_of_keycloak >= None < 26.4.9
cpe:2.3:a:redhat:build_of_keycloak:-:*:*:*:text-only:*:*:* build_of_keycloak == None == -
cpe:2.3:a:redhat:keycloak:*:*:*:*:*:*:*:* keycloak >= None < 26.4.0

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
keycloak edge-community 26.2.5-r0 Jakub Jirutka <jakub@jirutka.cz> possibly vulnerable
keycloak edge-community 26.2.1-r0 Jakub Jirutka <jakub@jirutka.cz> possibly vulnerable
keycloak edge-community 26.1.5-r0 Jakub Jirutka <jakub@jirutka.cz> possibly vulnerable
keycloak edge-community 26.1.3-r0 Jakub Jirutka <jakub@jirutka.cz> possibly vulnerable
keycloak edge-community 26.1.2-r1 Jakub Jirutka <jakub@jirutka.cz> possibly vulnerable
keycloak edge-community 26.1.2-r0 Jakub Jirutka <jakub@jirutka.cz> possibly vulnerable
keycloak edge-community 26.1.1-r0 Jakub Jirutka <jakub@jirutka.cz> possibly vulnerable
keycloak edge-community 26.0.7-r0 Jakub Jirutka <jakub@jirutka.cz> possibly vulnerable
keycloak edge-community 25.0.6-r1 Jakub Jirutka <jakub@jirutka.cz> possibly vulnerable
keycloak 3.23-community 26.2.5-r0 Jakub Jirutka <jakub@jirutka.cz> possibly vulnerable