
Sharing my latest security finding: CVE-2025-13881 in #Keycloak The issue was reported through @yeswehack and affects the Keycloak Admin API, where a limited admin could access user attributes that should not be exposed. More details in the redhat advisory: https://access.redhat.com/security/cve/cve-2025-13881 #cybersecurity #bugbounty #infosec #CVE #Keycloak #YesWeHack
Post summary
Keycloak Admin API vulnerability (CVE-2025-13881) disclosed by YesWeHack; allows limited admin to view user attributes; Red Hat advisory linked for details.

