Junglewise Threat Intelligence

CVE-2026-33584: Arqit Symmetric Key Agreement Platform information disclosure in Keycloak service

CVE-2026-33584 · Severity: medium · CVSS 5.3 · Published 2026-05-13

Technologies: Arqit Symmetric Key Agreement Platform. Vendors: Arqit.

Executive brief

The Arqit Symmetric Key Agreement Platform, which provides secure encryption key management, contains a configuration flaw that exposes internal diagnostic services. An unauthorized person could access sensitive system health data and performance metrics over the network. This information could be used by an attacker to gain insights into the system's internal operations or plan further attacks.

Technical details

The Arqit Symmetric Key Agreement Platform (SKA-Platform) fails to restrict access to the Keycloak management interface. This vulnerability, classified as CWE-749 (Exposed Dangerous Method or Function), allows a remote, unauthenticated attacker to retrieve sensitive debug information, including system metrics and health data, via unencrypted HTTP GET requests. The root cause is the exposure of an interface that Keycloak developers recommend keeping internal. The issue is resolved in version 26.03.

Affected products

  • Arqit Symmetric Key Agreement Platform before 26.03 (specifically 25.09.x and 25.12)

Timeline

  • 2026-05-13: advisory: Initial publication of CVE-2026-33584
  • 2026-05-13: disclosed: Vulnerability details made public by ENISA/CVCN

References

Related threats