REDHAT-BUG-2419086: Low severity Red Hat Keycloak vulnerability

Published Dec 5, 2025
·
Updated

An Improper Access Control vulnerability exists in the Keycloak Admin REST API, where a user possessing only the create-client permission—considered low-privilege by design—can unexpectedly access the /admin/realms/master/users/profile endpoint. This endpoint returns internal user profile schema data, including attribute names, validation rules, display metadata, and permission mappings. Although the attacker cannot view actual user accounts, the exposure of backend schema and rules results from insufficient authorization checks specifically on this endpoint. An authenticated but minimally privileged user can remotely retrieve sensitive configuration metadata, which may be leveraged to craft targeted attacks or prepare future privilege-escalation attempts.

Affected Software

1 affected component
Red Hat Keycloak

Event History

Dec 5, 2025
Data Sourced
via Red Hat·06:11 AM
DescriptionSeverityAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of REDHAT-BUG-2419086?

The severity of REDHAT-BUG-2419086 is considered medium due to improper access control that allows low-privilege users to access sensitive endpoints.

2

How do I fix REDHAT-BUG-2419086?

To mitigate REDHAT-BUG-2419086, review user permissions and ensure that appropriate access controls are applied to the Keycloak Admin REST API endpoints.

3

Which versions of Red Hat Keycloak are affected by REDHAT-BUG-2419086?

REDHAT-BUG-2419086 affects all versions of Red Hat Keycloak where the improper access control vulnerability is present.

4

What impact does REDHAT-BUG-2419086 have on user security?

The impact of REDHAT-BUG-2419086 compromises user privacy by allowing unauthorized access to internal user profile data.

5

Are there any workarounds for REDHAT-BUG-2419086?

A potential workaround for REDHAT-BUG-2419086 is to temporarily restrict low-privilege users from accessing sensitive API endpoints until a patch is applied.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203