It was found that Keycloak before version 12.0.0 would permit a user with only view-profile role to manage the resources in the new account console, allowing access and modification of data the user was not intended to have.
https://github.com/advisories/GHSA-c9x9-xv66-xp3v
https://euvd.enisa.europa.eu/vulnerability/EUVD-2021-2335