CVE-2025-13881

Published Feb 2, 2026

Last updated a day ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2025-13881 describes a vulnerability in Keycloak where a limited administrator can access sensitive user attributes that should otherwise be hidden. Specifically, the Keycloak Admin API's `/unmanagedAttributes` endpoint does not properly enforce the visibility configurations set within the User Profile settings. This flaw allows an administrator with restricted privileges, such as those holding the `view-users` role, to retrieve sensitive custom attributes like phone numbers or personal addresses. These attributes are explicitly configured to be hidden from both users and administrators through the graphical user interface. The vulnerability is categorized as an Incorrect Privilege Assignment (CWE-266).

Description
A flaw was found in Keycloak Admin API. This vulnerability allows an administrator with limited privileges to retrieve sensitive custom attributes via the /unmanagedAttributes endpoint, bypassing User Profile visibility settings.
Source
secalert@redhat.com
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Primary
Base score
2.7
Impact score
1.4
Exploitability score
1.2
Vector string
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
Severity
LOW

Weaknesses

secalert@redhat.com
CWE-266

Social media

Hype score
Not currently trending