Keycloak: keycloak: information disclosure through arbitrary filesystem path probing
Summary
| CVE | CVE-2026-9083 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-06-25 17:17:03 UTC |
| Updated | 2026-07-01 17:22:17 UTC |
| Description | A flaw was found in Keycloak. A realm administrator with the "manage-realm" role can exploit this vulnerability by submitting an arbitrary filesystem path as a keystore parameter when creating a key provider component. This allows the administrator to probe arbitrary filesystem paths, determining which files exist and are readable by the Keycloak process. This information disclosure could be used to identify high-value targets for follow-on attacks. |
Risk And Classification
Primary CVSS: v3.1 4.9 MEDIUM from [email protected]
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
EPSS: 0.005190000 probability, percentile 0.402850000 (date 2026-07-04)
Problem Types: CWE-22 | CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 4.9 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N |
| 3.1 | CNA | CVSS | 4.9 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N |
CVSS v3.1 Breakdown
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Redhat | Build Of Keycloak | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Red Hat | Red Hat Build Of Keycloak 26.4 | unaffected 26.4.13-1 * rpm | Not specified |
| CNA | Red Hat | Red Hat Build Of Keycloak 26.4 | unaffected 26.4-19 * rpm | Not specified |
| CNA | Red Hat | Red Hat Build Of Keycloak 26.4 | unaffected 26.4-19 * rpm | Not specified |
| CNA | Red Hat | Red Hat Build Of Keycloak 26.4.13 | Not specified | Not specified |
| CNA | Red Hat | Red Hat Build Of Keycloak 26.6 | unaffected 26.6.4-2 * rpm | Not specified |
| CNA | Red Hat | Red Hat Build Of Keycloak 26.6 | unaffected 26.6-8 * rpm | Not specified |
| CNA | Red Hat | Red Hat Build Of Keycloak 26.6 | unaffected 26.6-8 * rpm | Not specified |
| CNA | Red Hat | Red Hat Build Of Keycloak 26.6.4 | Not specified | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| access.redhat.com/errata/RHSA-2026:30083 | [email protected] | access.redhat.com | Third Party Advisory |
| bugzilla.redhat.com/show_bug.cgi | [email protected] | bugzilla.redhat.com | Third Party Advisory |
| access.redhat.com/errata/RHSA-2026:30084 | [email protected] | access.redhat.com | Third Party Advisory |
| access.redhat.com/security/cve/CVE-2026-9083 | [email protected] | access.redhat.com | Third Party Advisory |
| access.redhat.com/errata/RHSA-2026:30049 | [email protected] | access.redhat.com | Third Party Advisory |
| access.redhat.com/errata/RHSA-2026:30050 | [email protected] | access.redhat.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Red Hat would like to thank Swapnil Paliwal & Security Team (AxiomCode) for reporting this issue. (en)
Additional Advisory Data
| Source | Time | Event |
|---|---|---|
| CNA | 2026-05-20T14:11:24.606Z | Reported to Red Hat. |
| CNA | 2026-06-25T15:58:16.784Z | Made public. |
Workarounds
CNA: Ensure that only highly trusted administrators are granted the "manage-realm" role within Keycloak. This role provides extensive administrative privileges, including the ability to exploit this vulnerability for filesystem probing. Regularly review and audit users assigned to this role to minimize the attack surface.