CVE-2026-9083 Details
Description
A flaw was found in Keycloak. A realm administrator with the "manage-realm" role can exploit this vulnerability by submitting an arbitrary filesystem path as a keystore parameter when creating a key provider component. This allows the administrator to probe arbitrary filesystem paths, determining which files exist and are readable by the Keycloak process. This information disclosure could be used to identify high-value targets for follow-on attacks.
A vulnerability exists in Keycloak that allows a realm administrator with the 'manage-realm' role to probe arbitrary filesystem paths. By submitting a crafted keystore parameter while creating a key provider component, the administrator can determine which files are readable by the Keycloak process. This information disclosure could be leveraged to identify high-value targets for subsequent attacks.
It is recommended to limit the 'manage-realm' role to trusted administrators only and to regularly review and audit users assigned to this role.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 25, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2026:30049 | [email protected] | Third Party Advisory |
| https://access.redhat.com/errata/RHSA-2026:30050 | [email protected] | Third Party Advisory |
| https://access.redhat.com/errata/RHSA-2026:30083 | [email protected] | Third Party Advisory |
| https://access.redhat.com/errata/RHSA-2026:30084 | [email protected] | Third Party Advisory |
| https://access.redhat.com/security/cve/CVE-2026-9083 | [email protected] | Third Party Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2480168 | [email protected] | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| redhat build of keycloak | >= 26.4, < 26.4.13 >= 26.6, < 26.6.4 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 1, 2026 | Reanalysis | [email protected] |
| Jul 1, 2026 | Initial Analysis | [email protected] |
| Jun 26, 2026 | CVE Modified | [email protected] |
| Jun 25, 2026 | CVE Modified | [email protected] |
| Jun 25, 2026 | CVE Modified | CISA-ADP |
| Jun 25, 2026 | New CVE Received | [email protected] |