CVE-2026-9083
Undergoing Analysis Undergoing Analysis - In Progress
Keycloak Information Disclosure via Arbitrary File Path

Publication date: 2026-06-25

Last updated on: 2026-06-25

Assigner: Red Hat, Inc.

Description
A flaw was found in Keycloak. A realm administrator with the "manage-realm" role can exploit this vulnerability by submitting an arbitrary filesystem path as a keystore parameter when creating a key provider component. This allows the administrator to probe arbitrary filesystem paths, determining which files exist and are readable by the Keycloak process. This information disclosure could be used to identify high-value targets for follow-on attacks.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-25
Last Modified
2026-06-25
Generated
2026-06-26
AI Q&A
2026-06-25
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 3 associated CPEs
Vendor Product Version / Range
keycloak keycloak *
redhat keycloak From 2026-05-20 (inc)
redhat keycloak *
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-22 The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability exists in Keycloak and can be exploited by a realm administrator who has the "manage-realm" role.

The attacker can submit an arbitrary filesystem path as a keystore parameter when creating a key provider component.

This allows the attacker to probe arbitrary filesystem paths to determine which files exist and are readable by the Keycloak process.

The disclosed information can then be used to identify high-value targets for further attacks.

Impact Analysis

The vulnerability can lead to information disclosure by allowing a realm administrator to discover files on the filesystem that are accessible to the Keycloak process.

This information can be leveraged to identify sensitive or high-value files, which could be targeted in subsequent attacks.

While it does not directly allow modification or deletion of files, the exposure of file existence and readability can increase the risk of further exploitation.

Detection Guidance

This vulnerability involves a realm administrator submitting an arbitrary filesystem path as a keystore parameter when creating a key provider component in Keycloak. Detection would involve monitoring for such unusual or unauthorized keystore parameter inputs by users with the "manage-realm" role.

There are no specific commands or automated detection methods provided in the available information to detect exploitation attempts or presence of this vulnerability on your system or network.

Mitigation Strategies

The provided information does not include explicit mitigation steps or recommended immediate actions to address this vulnerability.

Compliance Impact

The provided information does not specify how this vulnerability affects compliance with common standards and regulations such as GDPR or HIPAA.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-9083. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart