Keycloak Services Vulnerability in Red Hat Build by Red Hat
CVE-2026-19729
4.9MEDIUM
What is CVE-2026-19729?
A vulnerability exists in the key provider component of the keycloak-services library, which serves as the core engine for the Red Hat Build of Keycloak. This flaw arises from an incomplete previous update concerning path probing. As a consequence, a realm administrator can still submit arbitrary filesystem paths as keystore parameters. This misconfiguration could enable the unauthorized determination of file existence and readability on the server, thereby risking the exposure of sensitive information stored in the filesystem.
References
CVSS V3.1
Score:
4.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Audax Financial Technology for reporting this issue.