CVE-2026-19729
Awaiting Analysis Awaiting Analysis - Queue

Path Traversal in Red Hat Build of Keycloak

Vulnerability report for CVE-2026-19729, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-09

Assigner: redhat-SADP

Description

A flaw was found in the key provider component of the keycloak-services library, which is the core engine for the Red Hat Build of Keycloak. The issue occurs because a previous fix for path probing was incomplete, allowing a realm administrator to still submit arbitrary filesystem paths as keystore parameters. This can be used to determine the existence and readability of files on the server, potentially exposing sensitive system information.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-09
Generated
2026-09-29
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
red_hat keycloak_services *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-22 The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a flaw in the key provider component of the keycloak-services library, which is the core engine for Red Hat Build of Keycloak. It occurs because a previous fix for path probing was incomplete, allowing a realm administrator to submit arbitrary filesystem paths as keystore parameters. This can be used to check if files exist and are readable on the server, potentially exposing sensitive system information.

Detection Guidance

Detecting this vulnerability requires checking for improper path probing in the Keycloak key provider component. Review Keycloak server logs for unusual keystore parameter submissions or file existence checks. Monitor for realm administrators attempting to access arbitrary filesystem paths. No specific commands are provided in the context, but inspect Keycloak configuration files and audit logs for suspicious activity related to keystore path handling.

Impact Analysis

The impact is limited to confidentiality breaches. An attacker with realm administrator privileges (manage-realm role) could determine the existence and readability of files on the server. This does not allow modification or deletion of files but could expose sensitive system information, such as configuration files or other restricted data.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by exposing sensitive system information. GDPR requires protection of personal data, and HIPAA mandates safeguarding protected health information. Unauthorized access to system files could lead to data breaches, violating these regulations and resulting in legal or financial penalties.

Mitigation Strategies

Immediate mitigation steps include restricting realm administrator privileges to only necessary actions and avoiding the use of arbitrary filesystem paths in keystore parameters. Since no official mitigation is currently available, consider temporarily disabling the key provider component if feasible. Monitor Red Hat's official advisories for updates and apply patches once released. Review and tighten filesystem permissions to limit access to sensitive files.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19729. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart