No advisories yet.
Solution
No solution given by the vendor.
Workaround
Ensure that only highly trusted administrators are granted the "manage-realm" role within Keycloak. This role provides extensive administrative privileges, including the ability to exploit this vulnerability for filesystem probing. Regularly review and audit users assigned to this role to minimize the attack surface.
Thu, 25 Jun 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 25 Jun 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in Keycloak. A realm administrator with the "manage-realm" role can exploit this vulnerability by submitting an arbitrary filesystem path as a keystore parameter when creating a key provider component. This allows the administrator to probe arbitrary filesystem paths, determining which files exist and are readable by the Keycloak process. This information disclosure could be used to identify high-value targets for follow-on attacks. | |
| Title | Keycloak: keycloak: information disclosure through arbitrary filesystem path probing | |
| First Time appeared |
Redhat
Redhat build Keycloak |
|
| Weaknesses | CWE-22 | |
| CPEs | cpe:/a:redhat:build_keycloak: | |
| Vendors & Products |
Redhat
Redhat build Keycloak |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-06-25T17:53:44.159Z
Reserved: 2026-05-20T14:11:59.940Z
Link: CVE-2026-9083
Updated: 2026-06-25T17:53:36.331Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-25T18:15:04Z