Authorization Flaw in Keycloak Admin REST API Exposes Sensitive Client Secrets
CVE-2026-17048
5.5MEDIUM
What is CVE-2026-17048?
A security flaw in the Keycloak Admin REST API allows delegated administrators with view-only permissions to improperly access sensitive client secrets. This occurs when processing requests for rotated client secrets stored within a secure vault. The lack of proper boundary enforcement can lead to the exposure of confidential credentials, potentially compromising system security. Organizations using Keycloak should assess their implementations and apply necessary security patches to mitigate risks associated with this vulnerability.
References
CVSS V3.1
Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank yd1ng for reporting this issue.