A flaw was found in Keycloak Admin API. This vulnerability allows an administrator with limited privileges to retrieve sensitive custom attributes via the /unmanagedAttributes endpoint, bypassing User Profile visibility settings.
History

Mon, 02 Feb 2026 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 02 Feb 2026 06:00:00 +0000

Type Values Removed Values Added
Description No description is available for this CVE. A flaw was found in Keycloak Admin API. This vulnerability allows an administrator with limited privileges to retrieve sensitive custom attributes via the /unmanagedAttributes endpoint, bypassing User Profile visibility settings.
Title org.keycloak.services.resources.admin: Keycloak: Limited administrator can retrieve sensitive user attributes via Admin API Org.keycloak.services.resources.admin: keycloak: limited administrator can retrieve sensitive user attributes via admin api
First Time appeared Redhat
Redhat build Keycloak
CPEs cpe:/a:redhat:build_keycloak:
Vendors & Products Redhat
Redhat build Keycloak
References

Wed, 28 Jan 2026 00:15:00 +0000

Type Values Removed Values Added
Description No description is available for this CVE.
Title org.keycloak.services.resources.admin: Keycloak: Limited administrator can retrieve sensitive user attributes via Admin API
Weaknesses CWE-266
References
Metrics threat_severity

None

cvssV3_1

{'score': 2.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N'}

threat_severity

Low


cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2026-02-02T05:43:22.720Z

Updated: 2026-02-02T16:28:48.543Z

Reserved: 2025-12-02T14:06:42.988Z

Link: CVE-2025-13881

cve-icon Vulnrichment

Updated: 2026-02-02T16:25:09.009Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-02-02T06:16:19.453

Modified: 2026-02-03T16:44:36.630

Link: CVE-2025-13881

cve-icon Redhat

Severity : Low

Publid Date: 2026-01-27T12:34:00Z

Links: CVE-2025-13881 - Bugzilla