Skip to content

Keycloak Server Private SPI: Improper Access Control Allows Administrators to Bypass Attribute Visibility Restrictions and Modify Unmanaged User Profile Attributes

Moderate severity GitHub Reviewed Published Feb 27, 2026 to the GitHub Advisory Database • Updated Feb 28, 2026

No open alerts for this advisory

Give feedback on Dependabot alerts