๐Ÿ” CVE Alert

CVE-2026-19729

MEDIUM 4.9

Keycloak-services: keycloak-services: incomplete fix for arbitrary filesystem path probing via keystore parameters

CVSS Score
4.9
EPSS Score
0.0%
EPSS Percentile
0th

A flaw was found in the key provider component of the keycloak-services library, which is the core engine for the Red Hat Build of Keycloak. The issue occurs because a previous fix for path probing was incomplete, allowing a realm administrator to still submit arbitrary filesystem paths as keystore parameters. This can be used to determine the existence and readability of files on the server, potentially exposing sensitive system information.

CWE CWE-22
Vendor red hat
Product red hat build of keycloak
Published Sep 9, 2026
Last Updated Sep 9, 2026
Stay Ahead of the Next One

Get instant alerts for red hat red hat build of keycloak

Be the first to know when new medium vulnerabilities affecting red hat red hat build of keycloak are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

Red Hat / Red Hat Build of Keycloak
All versions affected
Red Hat / Red Hat Build of Keycloak
All versions affected
Red Hat / Red Hat Single Sign-On 7
All versions affected

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
access.redhat.com: https://access.redhat.com/security/cve/CVE-2026-19729 bugzilla.redhat.com: https://bugzilla.redhat.com/show_bug.cgi?id=2515294

Credits

Red Hat would like to thank Audax Financial Technology for reporting this issue.