CVE-2021-4133 is a high-severity vulnerability affecting Keycloak versions 12.0.0 through 15.1.0, allowing an authenticated attacker to create new default user accounts via the administrative REST API, even when new user registration is disabled. With a CVSS score of 8.8, this flaw presents a low-complexity attack vector that can lead to high impact on confidentiality, integrity, and availability. While the vulnerability is not listed on the KEV catalog and has no known public exploits or significant community discussion, its potential for unauthorized account creation poses a significant risk. Organizations using affected Keycloak versions should prioritize patching to mitigate this threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 12.0.0, < 15.1.1CPE matchmatch criteria | cpe:2.3:a:redhat:keycloak:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.