
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-13881 is an information disclosure vulnerability in the Keycloak Admin API (org.keycloak.services.resources.admin) that allows a limited-privilege administrator to retrieve sensitive custom user attributes by querying the /unmanagedAttributes endpoint, bypassing User Profile visibility settings. It was reported on December 2, 2025, and publicly disclosed on January 27, 2026. Affected versions of org.keycloak:keycloak-services include all releases before 26.4.9 and versions 26.5.0 through 26.5.1. It carries a CVSS v3.1 base score of 2.7 (Low) (Red Hat CVE, Github Advisory).
The root cause is classified as CWE-266 (Incorrect Privilege Assignment): the /unmanagedAttributes Admin API endpoint fails to enforce the visibility restrictions configured in Keycloak's User Profile feature, allowing attributes explicitly marked as hidden from both users and administrators in the GUI to be returned via the API (Github Advisory, Red Hat Bugzilla). Exploitation requires three preconditions: the attacker must have a valid account in the target realm, must hold the view-users role (an administrative privilege), and the realm must use the User Profile feature with custom attributes configured for restricted visibility. The attack is delivered over the network with no user interaction required, making it straightforward for any qualifying administrator to exploit by issuing a direct API call to the affected endpoint (Red Hat Bugzilla).
Successful exploitation results in unauthorized disclosure of sensitive custom user attributes — such as phone numbers or personal addresses — that administrators have explicitly configured to be hidden. The impact is limited to confidentiality (low), with no effect on integrity or availability, and is scoped to the affected Keycloak realm. While lateral movement is not directly enabled, exposure of personal data could facilitate social engineering or violate data protection regulations (Github Advisory, Red Hat Bugzilla).
view-users role.POST /realms/{realm}/protocol/openid-connect/token)./admin/realms/{realm}/users/{userId}/unmanagedAttributes endpoint using the obtained token./admin/realms/{realm}/users/{userId}/unmanagedAttributes from accounts that do not typically access this endpoint.unmanagedAttributes endpoint by accounts holding only the view-users role, particularly outside normal administrative workflows.Red Hat has released patched versions addressing this vulnerability: org.keycloak:keycloak-services versions 26.4.9 and 26.5.2. Red Hat build of Keycloak security advisories RHSA-2026:2365 (standalone) and RHSA-2026:2366 (OpenShift container images) were issued on February 9, 2026. Organizations should upgrade to the patched versions as the primary remediation; as a temporary measure, administrators can review and restrict the assignment of the view-users role to only fully trusted personnel (Github Advisory, Red Hat RHSA-2026:2365, Red Hat RHSA-2026:2366).
CVE-2025-13881 was noted in a Reddit CVEWatch post listing it among the top 10 trending CVEs around February 2, 2026, and was referenced in a Loginsoft threat intelligence blog covering active exploitation trends in core ecosystems. Community reaction has been muted given the low CVSS score and the requirement for elevated privileges to exploit the vulnerability.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."