PatchSiren cyber security CVE debrief
CVE-2026-9083 Red Hat CVE debrief
A flaw was found in Keycloak, a popular open-source identity and access management solution. A realm administrator with the 'manage-realm' role can exploit this vulnerability by submitting an arbitrary filesystem path as a keystore parameter when creating a key provider component. This allows the administrator to probe arbitrary filesystem paths, determining which files exist and are readable by the Keycloak process. This information disclosure could be used to identify high-value targets for follow-on attacks. The vulnerability has a CVSS score of 4.9 and is classified as MEDIUM severity.
- Vendor
- Red Hat
- Product
- Red Hat build of Keycloak 26.4
- CVSS
- MEDIUM 4.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-25
- Original CVE updated
- 2026-07-01
- Advisory published
- 2026-06-25
- Advisory updated
- 2026-07-01
Who should care
Keycloak administrators and users, especially those with the 'manage-realm' role, should be aware of this vulnerability and take necessary precautions. This vulnerability could be particularly concerning for organizations that use Keycloak for identity and access management, as it could potentially allow attackers to gather sensitive information about the system. Red Hat Build of Keycloak versions 26.4 and 26.6 are affected.
Technical summary
The vulnerability exists in the Keycloak component responsible for creating key providers. A realm administrator can submit an arbitrary filesystem path as a keystore parameter, allowing them to probe the filesystem and determine which files exist and are readable. This is possible because the application does not properly validate or sanitize the input provided by the administrator. The Common Vulnerabilities and Exposures (CVE) project has assigned CVE-2026-9083 to this issue.
Defensive priority
This vulnerability should be prioritized for remediation, especially in environments where Keycloak is used for sensitive applications or data. Administrators should review their systems for exposure and apply patches or mitigations as soon as possible.
Recommended defensive actions
- Review and apply patches or updates provided by Red Hat for Keycloak versions 26.4 and 26.6.
- Restrict access to the 'manage-realm' role to only trusted administrators.
- Monitor Keycloak logs for suspicious activity related to key provider creation.
- Implement additional security controls, such as file system access restrictions, to limit the potential impact of this vulnerability.
- Consider using compensating controls, such as Web Application Firewalls (WAFs), to detect and prevent exploitation attempts.
Evidence notes
The CVE-2026-9083 vulnerability was publicly disclosed on June 25, 2026, and has since been modified on July 1, 2026. The vulnerability affects Red Hat Build of Keycloak versions 26.4 and 26.6. The Common Vulnerability Scoring System (CVSS) score for this vulnerability is 4.9, indicating a MEDIUM severity level.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-9083 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-9083
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-9083 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-9083
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:30049
[email protected] - Third Party Advisory
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:30050
[email protected] - Third Party Advisory
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:30083
[email protected] - Third Party Advisory
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:30084
[email protected] - Third Party Advisory
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://access.redhat.com/security/cve/CVE-2026-9083
[email protected] - Third Party Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.