CVE Feed

    Dashboard / CVE / CVE-2026-9083

    CVE-2026-9083

    A flaw was found in Keycloak. A realm administrator with the "manage-realm" role can exploit this vulnerability by submitting an arbitrary filesystem path as a keystore parameter when creating a key provider component. This allows the administrator to probe arbitrary filesystem paths, determining which files exist and are readable by the Keycloak process. This information disclosure could be used to identify high-value targets for follow-on attacks.

    Published:Jun 25, 2026
    Last Modified:Jun 26, 2026
    EPS:Jun 25, 2026
    EPSS Score:
    CVSS Score:4.9

    Affected Products

    Vendor
    Redhat
    Product
    Build Keycloak
    Vendor
    Redhat
    Product
    Build Of Keycloak

    Exploits

    No exploit reference

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High