Information Disclosure Vulnerability in Keycloak by Red Hat
CVE-2026-9083

4.9MEDIUM

What is CVE-2026-9083?

A significant vulnerability has been identified in Keycloak, affecting realm administrators with the 'manage-realm' role. By exploiting this flaw, an administrator can input arbitrary filesystem paths when setting up key provider components. This could lead to information disclosure, allowing them to ascertain the existence and readability of various files within the Keycloak process environment. Such insights may pave the way for subsequent targeted attacks, emphasizing the need for immediate attention and mitigation strategies.

Affected Version(s)

Red Hat build of Keycloak 26.4 26.4.13-1

Red Hat build of Keycloak 26.4 26.4-19

Red Hat build of Keycloak 26.4 26.4-19

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Swapnil Paliwal & Security Team (AxiomCode) for reporting this issue.
.