Keycloak: keycloak: information disclosure through arbitrary filesystem path probing
Published Jun 25, 2026
4.9
MEDIUMCVSS 3.1
EPSS 0.78%
Description
A flaw was found in Keycloak. A realm administrator with the "manage-realm" role can exploit this vulnerability by submitting an arbitrary filesystem path as a keystore parameter when creating a key provider component. This allows the administrator to probe arbitrary filesystem paths, determining which files exist and are readable by the Keycloak process. This information disclosure could be used to identify high-value targets for follow-on attacks.
Affected products
No data.
- ≥ 26.4 · < 26.4.13
- ≥ 26.6 · < 26.6.4
No data.
Red Hat build of Keycloak 26.4
rhbk/keycloak-operator-bundle:26.4.13-1
Fixed · RHSA-2026:30050
Red Hat build of Keycloak 26.4
rhbk/keycloak-rhel9-operator:26.4-19
Fixed · RHSA-2026:30050
Red Hat build of Keycloak 26.4
rhbk/keycloak-rhel9:26.4-19
Fixed · RHSA-2026:30050
Red Hat build of Keycloak 26.4.13
rhbk/keycloak-rhel9
Fixed · RHSA-2026:30049
Red Hat build of Keycloak 26.6
rhbk/keycloak-operator-bundle:26.6.4-2
Fixed · RHSA-2026:30084
Red Hat build of Keycloak 26.6
rhbk/keycloak-rhel9-operator:26.6-8
Fixed · RHSA-2026:30084
Red Hat build of Keycloak 26.6
rhbk/keycloak-rhel9:26.6-8
Fixed · RHSA-2026:30084
Red Hat build of Keycloak 26.6.4
rhbk/keycloak-rhel9
Fixed · RHSA-2026:30083
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat build of Keycloak 26.4 | rhbk/keycloak-operator-bundle:26.4.13-1 | Fixed | RHSA-2026:30050 |
| Red Hat build of Keycloak 26.4 | rhbk/keycloak-rhel9-operator:26.4-19 | Fixed | RHSA-2026:30050 |
| Red Hat build of Keycloak 26.4 | rhbk/keycloak-rhel9:26.4-19 | Fixed | RHSA-2026:30050 |
| Red Hat build of Keycloak 26.4.13 | rhbk/keycloak-rhel9 | Fixed | RHSA-2026:30049 |
| Red Hat build of Keycloak 26.6 | rhbk/keycloak-operator-bundle:26.6.4-2 | Fixed | RHSA-2026:30084 |
| Red Hat build of Keycloak 26.6 | rhbk/keycloak-rhel9-operator:26.6-8 | Fixed | RHSA-2026:30084 |
| Red Hat build of Keycloak 26.6 | rhbk/keycloak-rhel9:26.6-8 | Fixed | RHSA-2026:30084 |
| Red Hat build of Keycloak 26.6.4 | rhbk/keycloak-rhel9 | Fixed | RHSA-2026:30083 |
No package ranges for this CVE.
Remediation
Vendor solution
Ensure that only highly trusted administrators are granted the "manage-realm" role within Keycloak. This role provides extensive administrative privileges, including the ability to exploit this vulnerability for filesystem probing. Regularly review and audit users assigned to this role to minimize the attack surface.
Red Hat statement
Medium: This flaw in Keycloak allows a highly privileged realm administrator with the "manage-realm" role to perform arbitrary filesystem path probing. By submitting a crafted keystore path, an authenticated attacker can determine the existence and readability of files on the Keycloak server, potentially identifying high-value targets for further attacks. Exploitation requires an attacker to possess the "manage-realm" role, which is a high-level administrative permission.
Red Hat mitigation
Ensure that only highly trusted administrators are granted the "manage-realm" role within Keycloak. This role provides extensive administrative privileges, including the ability to exploit this vulnerability for filesystem probing. Regularly review and audit users assigned to this role to minimize the attack surface.
References (8)
- https://access.redhat.com/errata/RHSA-2026:30049 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2026:30050 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2026:30083 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2026:30084 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2026-9083 vdb-entryx_refsource_REDHATThird Party AdvisoryVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2480168 issue-trackingx_refsource_REDHATThird Party AdvisoryIssue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2026-9083
- https://www.cve.org/CVERecord?id=CVE-2026-9083
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2026:30049 | vendor-advisoryx_refsource_REDHATThird Party Advisory | |
| https://access.redhat.com/errata/RHSA-2026:30050 | vendor-advisoryx_refsource_REDHATThird Party Advisory | |
| https://access.redhat.com/errata/RHSA-2026:30083 | vendor-advisoryx_refsource_REDHATThird Party Advisory | |
| https://access.redhat.com/errata/RHSA-2026:30084 | vendor-advisoryx_refsource_REDHATThird Party Advisory | |
| https://access.redhat.com/security/cve/CVE-2026-9083 | vdb-entryx_refsource_REDHATThird Party AdvisoryVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2480168 | issue-trackingx_refsource_REDHATThird Party AdvisoryIssue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-9083 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-9083 |
Change history (0)
No recorded changes yet.