Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v4jw-m6rm-399h

Опубликовано: 27 фев. 2026
Источник: github
Github: Прошло ревью
CVSS3: 4.9

Описание

Keycloak Server Private SPI: Improper Access Control Allows Administrators to Bypass Attribute Visibility Restrictions and Modify Unmanaged User Profile Attributes

A flaw was found in Keycloak. An administrator with manage-users permission can bypass the "Only administrators can view" setting for unmanaged attributes, allowing them to modify these attributes. This improper access control can lead to unauthorized changes to user profiles, even when the system is configured to restrict such modifications.

Пакеты

Наименование

org.keycloak:keycloak-server-spi-private

maven
Затронутые версииВерсия исправления

< 26.5.2

26.5.2

EPSS

Процентиль: 23%
0.00307
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-266
CWE-284

Связанные уязвимости

CVSS3: 4.9
redhat
больше 1 года назад

A flaw was found in Keycloak. An administrator with `manage-users` permission can bypass the "Only administrators can view" setting for unmanaged attributes, allowing them to modify these attributes. This improper access control can lead to unauthorized changes to user profiles, even when the system is configured to restrict such modifications.

CVSS3: 4.9
nvd
6 месяцев назад

A flaw was found in Keycloak. An administrator with `manage-users` permission can bypass the "Only administrators can view" setting for unmanaged attributes, allowing them to modify these attributes. This improper access control can lead to unauthorized changes to user profiles, even when the system is configured to restrict such modifications.

CVSS3: 4.9
debian
6 месяцев назад

A flaw was found in Keycloak. An administrator with `manage-users` per ...

EPSS

Процентиль: 23%
0.00307
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-266
CWE-284