Keycloak User Resource Component Information Disclosure Vulnerability

Vulnerability

A vulnerability exists in Keycloak's UserResource component, allowing an authenticated user with the view-users role to access a specific administrative endpoint and retrieve user attributes that are meant to be hidden. This flaw leads to unauthorized disclosure of sensitive user information, as it violates the privacy settings intended to keep these attributes concealed from both users and administrators.

Impact

Exploitation of this vulnerability could result in the unauthorized disclosure of private user attributes that are disabled and not meant to be viewed by any context.

Reproduction

To reproduce this vulnerability, an authenticated user with the view-users role must access the administrative endpoint /admin/realms/{realm}/users/{UUID}/unmanagedAttributes. This endpoint will return user attributes that are configured to be hidden, thereby disclosing information that should not be accessible.

Added: Mar 11, 2026, 6:19 AM
Updated: Mar 11, 2026, 6:19 AM

Vulnerability Rating

Custom Algorithm
spread
5.2
impact
0.6
exploitability
6.4
remediation
0.0
relevance
3.8
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.