Executive brief
The Red Hat Build of Keycloak's key provider component contains an incomplete fix that allows realm administrators to submit arbitrary filesystem paths, enabling them to probe the server's filesystem and determine the existence and readability of sensitive files. This can expose system information and compromise operational security without requiring network access or additional privileges beyond administrative control of a realm.
Technical details
A path traversal/disclosure vulnerability exists in the key provider component of the keycloak-services library due to an incomplete remediation of a prior path probing fix. The vulnerability allows an authenticated realm administrator to supply arbitrary filesystem paths as keystore parameters, enabling information disclosure through filesystem path enumeration. An attacker with realm administrator privileges can determine file existence and readability on the underlying server, potentially exposing sensitive system configuration and credential paths. A patch is expected from Red Hat; organizations should monitor for and apply security updates to the Red Hat Build of Keycloak.
Affected products
- Red Hat Keycloak <UNKNOWN>
Timeline
- 2026-09-09: disclosed