
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-0871 is an improper access control vulnerability in Keycloak (and Red Hat build of Keycloak) that allows an administrator with manage-users permission to bypass the "Only administrators can view" restriction on unmanaged user attributes, enabling unauthorized modification of those attributes. It affects Keycloak versions prior to 26.4.0 and Red Hat build of Keycloak versions prior to 26.4.9. The vulnerability was reported on January 13, 2026, and publicly disclosed on February 27, 2026. It carries a CVSS v3.1 base score of 4.9 (Medium) (Red Hat CVE, Red Hat Bugzilla).
The root cause is classified as CWE-266 (Incorrect Privilege Assignment): Keycloak's keycloak-services component fails to enforce the "Only administrators can view" restriction on unmanaged attributes when an administrator with manage-users permission issues update requests. The flaw allows such administrators to write arbitrary values to unmanaged user attributes — for example, via the kcadm.sh update users/<user-id> command or direct API calls — even when the realm is configured to restrict such modifications. Exploitation requires the realm to have unmanaged attributes set to "Only administrators can view" and the attacker to hold a manage-users privileged account (Red Hat Bugzilla, Red Hat CVE).
Successful exploitation allows a privileged administrator to make unauthorized changes to user profile attributes that are intended to be immutable or restricted, potentially corrupting sensitive user data or bypassing attribute-based access controls within the Keycloak realm. There is no confidentiality or availability impact; the risk is limited to integrity of user profile data. While lateral movement is not directly enabled, tampering with user attributes could undermine downstream authorization decisions that rely on those attributes (Red Hat Bugzilla, Red Hat CVE).
manage-users permission in a Keycloak realm where unmanaged attributes are configured to "Only administrators can view."kcadm.sh to identify the target user's UUID../kcadm.sh update users/<user-uuid> -r <realm> -s "attributes.sensitiveAttr=maliciousValue"UPDATE events on user resources (UPDATE_USER) by an administrator account with manage-users role, particularly targeting attributes not normally modified by that account.PUT /admin/realms/<realm>/users/<user-id> requests with attribute payloads that include unmanaged attribute names.Red Hat has released patches addressing this vulnerability: update Keycloak to version 26.4.0 or later, or Red Hat build of Keycloak to version 26.4.9 or later. Security advisories RHSA-2026:2365 (standalone packages) and RHSA-2026:2366 (OpenShift container images) are available from the Red Hat Customer Portal. As an interim measure, review and audit all administrator accounts holding manage-users permissions, and implement additional monitoring for unexpected user attribute modifications until patching is complete (RHSA-2026:2365, RHSA-2026:2366).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."