PT-2026-52505 · Red Hat · Keycloak

CVE-2026-9083

·

Published

2026-06-25

·

Updated

2026-08-25

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Keycloak (affected versions not specified)
Description A realm administrator with the manage-realm role can probe arbitrary filesystem paths by submitting an arbitrary path as a keystore parameter during the creation of a key provider component. This allows the user to determine which files exist and are readable by the Keycloak process, potentially identifying targets for further attacks.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-KEYCLOAK-2026-9083
CVE-2026-9083

Affected Products

Keycloak