CVE-2025-1391
A flaw was found in the Keycloak organization feature, which allows the incorrect assignment of an organization to a user if their username or email matches the organization’s domain pattern. This issue occurs at the mapper level, leading to misrepresentation in tokens. If an application relies on these claims for authorization, it may incorrectly assume a user belongs to an organization they are not a member of, potentially granting unauthorized access or privileges.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
- Puntuación base: 5.4
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.41%
- Percentil entre todas las CVEs puntuadas: 33
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-284
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-1391",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-1391",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2025-02-18T17:17:45.272663Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "secalert@redhat.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.4,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "LOW"
},
"impactScore": 2.5,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "secalert@redhat.com",
"affectedData": [
{
"versions": [
{
"status": "affected",
"version": "26.0.0",
"lessThan": "26.0.10",
"versionType": "semver"
}
],
"packageName": "keycloak-services",
"collectionURL": "https://github.com/keycloak/keycloak",
"defaultStatus": "unaffected"
},
{
"cpes": [
"cpe:/a:redhat:build_keycloak:26.0"
],
"vendor": "Red Hat",
"product": "Red Hat Build of Keycloak",
"packageName": "keycloak-services",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "unaffected"
},
{
"cpes": [
"cpe:/a:redhat:build_keycloak:26.0::el9"
],
"vendor": "Red Hat",
"product": "Red Hat build of Keycloak 26.0",
"versions": [
{
"status": "unaffected",
"version": "26.0.10-3",
"lessThan": "*",
"versionType": "rpm"
}
],
"packageName": "rhbk/keycloak-operator-bundle",
"collectionURL": "https://catalog.redhat.com/software/containers/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:build_keycloak:26.0::el9"
],
"vendor": "Red Hat",
"product": "Red Hat build of Keycloak 26.0",
"versions": [
{
"status": "unaffected",
"version": "26.0-11",
"lessThan": "*",
"versionType": "rpm"
}
],
"packageName": "rhbk/keycloak-rhel9",
"collectionURL": "https://catalog.redhat.com/software/containers/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:build_keycloak:26.0::el9"
],
"vendor": "Red Hat",
"product": "Red Hat build of Keycloak 26.0",
"versions": [
{
"status": "unaffected",
"version": "26.0-12",
"lessThan": "*",
"versionType": "rpm"
}
],
"packageName": "rhbk/keycloak-rhel9-operator",
"collectionURL": "https://catalog.redhat.com/software/containers/",
"defaultStatus": "affected"
}
]
}
],
"published": "2025-02-17T14:15:08.413",
"references": [
{
"url": "https://access.redhat.com/errata/RHSA-2025:2544",
"source": "secalert@redhat.com"
},
{
"url": "https://access.redhat.com/errata/RHSA-2025:2545",
"source": "secalert@redhat.com"
},
{
"url": "https://access.redhat.com/security/cve/CVE-2025-1391",
"source": "secalert@redhat.com"
},
{
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2346082",
"source": "secalert@redhat.com"
},
{
"url": "https://github.com/keycloak/keycloak/issues/37169",
"source": "secalert@redhat.com"
},
{
"url": "https://github.com/keycloak/keycloak/pull/37235",
"source": "secalert@redhat.com"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "secalert@redhat.com",
"description": [
{
"lang": "en",
"value": "CWE-284"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A flaw was found in the Keycloak organization feature, which allows the incorrect assignment of an organization to a user if their username or email matches the organization’s domain pattern. This issue occurs at the mapper level, leading to misrepresentation in tokens. If an application relies on these claims for authorization, it may incorrectly assume a user belongs to an organization they are not a member of, potentially granting unauthorized access or privileges."
},
{
"lang": "es",
"value": "Se encontró una falla en la función de organización de Keycloak, que permite la asignación incorrecta de una organización a un usuario si su nombre de usuario o correo electrónico coincide con el patrón de dominio de la organización. Este problema ocurre en el nivel del asignador, lo que genera una representación errónea en los tokens. Si una aplicación se basa en estas afirmaciones para la autorización, puede asumir incorrectamente que un usuario pertenece a una organización de la que no es miembro, lo que podría otorgar acceso o privilegios no autorizados."
}
],
"lastModified": "2026-09-21T06:17:00.010",
"sourceIdentifier": "secalert@redhat.com"
}