Keycloak Services Vulnerability in Red Hat Build by Red Hat
CVE-2026-19729

4.9MEDIUM

Key Information:

Vendor

Red Hat

Vendor
CVE Published:
9 September 2026

What is CVE-2026-19729?

A vulnerability exists in the key provider component of the keycloak-services library, which serves as the core engine for the Red Hat Build of Keycloak. This flaw arises from an incomplete previous update concerning path probing. As a consequence, a realm administrator can still submit arbitrary filesystem paths as keystore parameters. This misconfiguration could enable the unauthorized determination of file existence and readability on the server, thereby risking the exposure of sensitive information stored in the filesystem.

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Audax Financial Technology for reporting this issue.
.