Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v4jw-m6rm-399h

Опубликовано: 27 фев. 2026
Источник: github
Github: Прошло ревью
CVSS3: 4.9

Описание

Keycloak Server Private SPI: Improper Access Control Allows Administrators to Bypass Attribute Visibility Restrictions and Modify Unmanaged User Profile Attributes

A flaw was found in Keycloak. An administrator with manage-users permission can bypass the "Only administrators can view" setting for unmanaged attributes, allowing them to modify these attributes. This improper access control can lead to unauthorized changes to user profiles, even when the system is configured to restrict such modifications.

Пакеты

Наименование

org.keycloak:keycloak-server-spi-private

maven
Затронутые версииВерсия исправления

< 26.5.2

26.5.2

EPSS

Процентиль: 9%
0.00032
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-266
CWE-284

Связанные уязвимости

CVSS3: 4.9
redhat
около 1 года назад

A flaw was found in Keycloak. An administrator with `manage-users` permission can bypass the "Only administrators can view" setting for unmanaged attributes, allowing them to modify these attributes. This improper access control can lead to unauthorized changes to user profiles, even when the system is configured to restrict such modifications.

CVSS3: 4.9
nvd
около 1 месяца назад

A flaw was found in Keycloak. An administrator with `manage-users` permission can bypass the "Only administrators can view" setting for unmanaged attributes, allowing them to modify these attributes. This improper access control can lead to unauthorized changes to user profiles, even when the system is configured to restrict such modifications.

CVSS3: 4.9
debian
около 1 месяца назад

A flaw was found in Keycloak. An administrator with `manage-users` per ...

EPSS

Процентиль: 9%
0.00032
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-266
CWE-284