Back

MEDIUM

Keycloak: keycloak: information disclosure through arbitrary filesystem path probing

Published Jun 25, 2026

Description

A flaw was found in Keycloak. A realm administrator with the "manage-realm" role can exploit this vulnerability by submitting an arbitrary filesystem path as a keystore parameter when creating a key provider component. This allows the administrator to probe arbitrary filesystem paths, determining which files exist and are readable by the Keycloak process. This information disclosure could be used to identify high-value targets for follow-on attacks.

Affected products

Remediation

Vendor solution

Ensure that only highly trusted administrators are granted the "manage-realm" role within Keycloak. This role provides extensive administrative privileges, including the ability to exploit this vulnerability for filesystem probing. Regularly review and audit users assigned to this role to minimize the attack surface.

Red Hat statement

Medium: This flaw in Keycloak allows a highly privileged realm administrator with the "manage-realm" role to perform arbitrary filesystem path probing. By submitting a crafted keystore path, an authenticated attacker can determine the existence and readability of files on the Keycloak server, potentially identifying high-value targets for further attacks. Exploitation requires an attacker to possess the "manage-realm" role, which is a high-level administrative permission.

Red Hat mitigation

Ensure that only highly trusted administrators are granted the "manage-realm" role within Keycloak. This role provides extensive administrative privileges, including the ability to exploit this vulnerability for filesystem probing. Regularly review and audit users assigned to this role to minimize the attack surface.

Weaknesses (1)

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jun 25, 2026
Updated Jun 26, 2026
Reserved May 20, 2026
CISA Vulnrichment
Updated Jun 25, 2026
NVD
Status Analyzed
Modified Jul 1, 2026
Red Hat
Severity Moderate
Public date Jun 25, 2026
ENISA EUVD
Assigner n/a
Published n/a
Updated n/a
Exploited since n/a
Link n/a