A flaw was found in Keycloak. An administrator with `manage-users` permission can bypass the "Only administrators can view" setting for unmanaged attributes, allowing them to modify these attributes. This improper access control can lead to unauthorized changes to user profiles, even when the system is configured to restrict such modifications.
History

Fri, 27 Feb 2026 08:00:00 +0000

Type Values Removed Values Added
Description A flaw was found in Keycloak. An administrator with `manage-users` permission can bypass the "Only administrators can view" setting for unmanaged attributes, allowing them to modify these attributes. This improper access control can lead to unauthorized changes to user profiles, even when the system is configured to restrict such modifications.
Title Org.keycloak/keycloak-services: keycloak: unauthorized modification of unmanaged user attributes by administrators
First Time appeared Redhat
Redhat build Keycloak
Redhat jboss Enterprise Application Platform
Redhat jbosseapxp
Redhat red Hat Single Sign On
Weaknesses CWE-266
CPEs cpe:/a:redhat:build_keycloak:26.4::el9
cpe:/a:redhat:jboss_enterprise_application_platform:8
cpe:/a:redhat:jbosseapxp
cpe:/a:redhat:red_hat_single_sign_on:7
Vendors & Products Redhat
Redhat build Keycloak
Redhat jboss Enterprise Application Platform
Redhat jbosseapxp
Redhat red Hat Single Sign On
References
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-02-27T07:30:26.766Z

Reserved: 2026-01-13T08:41:28.810Z

Link: CVE-2026-0871

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-02-27T08:17:09.410

Modified: 2026-02-27T08:17:09.410

Link: CVE-2026-0871

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.