BIT-keycloak-2026-16104

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/keycloak/BIT-keycloak-2026-16104.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-keycloak-2026-16104
Aliases
  • CVE-2026-16104
Published
2026-08-31T14:37:00Z
Modified
2026-09-17T14:45:07Z
Summary
Keycloak-services: keycloak-services: authenticator config endpoint exposes raw recaptcha secrets to view-only admins
Details

A flaw was found in the authentication configuration endpoint of the keycloak-services component, which is the core engine for Red Hat Build of Keycloak identity and access management. The issue occurs because the system fails to mask sensitive configuration values, such as reCAPTCHA secret keys, when they are requested by administrators with view-only permissions. This can lead to the exposure of third-party service credentials to unauthorized personnel or through administrative logs.

Database specific
{
    "cpes": [
        "cpe:2.3:a:redhat:build_of_keycloak:*:*:*:*:-:*:*:*",
        "cpe:2.3:a:keycloak:keycloak:*:*:*:*:*:*:*:*"
    ],
    "severity": "Medium"
}
References

Affected packages

Bitnami / keycloak

Package

Name
keycloak
Purl
pkg:bitnami/keycloak

Severity

  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
26.7.3

Database specific

source
"https://github.com/bitnami/vulndb/tree/main/data/keycloak/BIT-keycloak-2026-16104.json"