BIT-keycloak-2026-9083

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/keycloak/BIT-keycloak-2026-9083.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-keycloak-2026-9083
Aliases
  • CVE-2026-9083
Published
2026-08-25T11:42:39.471Z
Modified
2026-08-26T11:15:12.055361226Z
Summary
Keycloak: keycloak: information disclosure through arbitrary filesystem path probing
Details

A flaw was found in Keycloak. A realm administrator with the "manage-realm" role can exploit this vulnerability by submitting an arbitrary filesystem path as a keystore parameter when creating a key provider component. This allows the administrator to probe arbitrary filesystem paths, determining which files exist and are readable by the Keycloak process. This information disclosure could be used to identify high-value targets for follow-on attacks.

Database specific
{
    "severity": "Medium",
    "cpes": [
        "cpe:2.3:a:redhat:build_of_keycloak:*:*:*:*:*:*:*:*",
        "cpe:2.3:a:keycloak:keycloak:*:*:*:*:*:*:*:*"
    ]
}
References

Affected packages

Bitnami / keycloak

Package

Name
keycloak
Purl
pkg:bitnami/keycloak

Severity

  • 4.9 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
26.4.0
Fixed
26.4.13
Introduced
26.6.0
Fixed
26.6.4

Database specific

source
"https://github.com/bitnami/vulndb/tree/main/data/keycloak/BIT-keycloak-2026-9083.json"