CVE Vulnerabilities

CVE-2026-0871

Incorrect Privilege Assignment

Published: Feb 27, 2026 | Modified: Mar 05, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
4.9 MODERATE
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
Ubuntu
root.io logo minimus.io logo echo.ai logo

A flaw was found in Keycloak. An administrator with manage-users permission can bypass the Only administrators can view setting for unmanaged attributes, allowing them to modify these attributes. This improper access control can lead to unauthorized changes to user profiles, even when the system is configured to restrict such modifications.

Weakness

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

Affected Software

NameVendorStart VersionEnd Version
Build_of_keycloakRedhat*26.4.9 (excluding)
Build_of_keycloakRedhat- (including)- (including)
KeycloakRedhat*26.4.0 (excluding)
Red Hat build of Keycloak 26.4RedHatrhbk/keycloak-operator-bundle:26.4.9-1*
Red Hat build of Keycloak 26.4RedHatrhbk/keycloak-rhel9:26.4-11*
Red Hat build of Keycloak 26.4RedHatrhbk/keycloak-rhel9-operator:26.4-10*
Red Hat build of Keycloak 26.4.9RedHatrhbk/keycloak-rhel9*

Potential Mitigations

References