CVE-2026-9083: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Red Hat Red Hat build of Keycloak 26.4
A flaw was found in Keycloak. A realm administrator with the "manage-realm" role can exploit this vulnerability by submitting an arbitrary filesystem path as a keystore parameter when creating a key provider component. This allows the administrator to probe arbitrary filesystem paths, determining which files exist and are readable by the Keycloak process. This information disclosure could be used to identify high-value targets for follow-on attacks.
AI Analysis
Technical Summary
The vulnerability CVE-2026-9083 in Red Hat build of Keycloak 26.4 involves improper limitation of a pathname to a restricted directory, enabling a realm administrator with the 'manage-realm' role to submit arbitrary filesystem paths as a keystore parameter during key provider component creation. This flaw allows the attacker to probe arbitrary filesystem paths to identify which files exist and are readable by the Keycloak process, resulting in information disclosure. The CVSS 3.1 base score is 4.9 (medium severity) with vector AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N, indicating network attack vector, low attack complexity, high privileges required, no user interaction, unchanged scope, high confidentiality impact, no integrity or availability impact. Red Hat published advisories (RHSA-2026:30049 and RHSA-2026:30050) listing this vulnerability among others fixed in Keycloak 26.4.13 packages and container images. However, these advisories do not explicitly confirm a patch or fix for CVE-2026-9083, and no patch links are provided. The advisories recommend backing up existing installations before applying updates. No known exploits in the wild have been reported.
Potential Impact
An attacker with realm administrator privileges can leverage this vulnerability to probe arbitrary filesystem paths on the Keycloak server, disclosing information about files that exist and are readable by the Keycloak process. This information disclosure could facilitate identification of sensitive files and high-value targets for subsequent attacks. There is no impact on integrity or availability. The vulnerability requires high privileges (realm administrator role) and no user interaction.
Mitigation Recommendations
Red Hat has released Keycloak 26.4.13 packages and container images addressing multiple security issues including CVE-2026-9083. Although the advisories do not explicitly confirm a patch for this specific vulnerability, applying the Keycloak 26.4.13 update is recommended. Before updating, back up all existing installations, configurations, and databases. Monitor Red Hat's official advisories for confirmation of patch status and further remediation guidance. No alternative mitigations or workarounds are specified.
CVE-2026-9083: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Red Hat Red Hat build of Keycloak 26.4
Description
A flaw was found in Keycloak. A realm administrator with the "manage-realm" role can exploit this vulnerability by submitting an arbitrary filesystem path as a keystore parameter when creating a key provider component. This allows the administrator to probe arbitrary filesystem paths, determining which files exist and are readable by the Keycloak process. This information disclosure could be used to identify high-value targets for follow-on attacks.
CVSS v3.1
Score 4.9medium
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability CVE-2026-9083 in Red Hat build of Keycloak 26.4 involves improper limitation of a pathname to a restricted directory, enabling a realm administrator with the 'manage-realm' role to submit arbitrary filesystem paths as a keystore parameter during key provider component creation. This flaw allows the attacker to probe arbitrary filesystem paths to identify which files exist and are readable by the Keycloak process, resulting in information disclosure. The CVSS 3.1 base score is 4.9 (medium severity) with vector AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N, indicating network attack vector, low attack complexity, high privileges required, no user interaction, unchanged scope, high confidentiality impact, no integrity or availability impact. Red Hat published advisories (RHSA-2026:30049 and RHSA-2026:30050) listing this vulnerability among others fixed in Keycloak 26.4.13 packages and container images. However, these advisories do not explicitly confirm a patch or fix for CVE-2026-9083, and no patch links are provided. The advisories recommend backing up existing installations before applying updates. No known exploits in the wild have been reported.
Potential Impact
An attacker with realm administrator privileges can leverage this vulnerability to probe arbitrary filesystem paths on the Keycloak server, disclosing information about files that exist and are readable by the Keycloak process. This information disclosure could facilitate identification of sensitive files and high-value targets for subsequent attacks. There is no impact on integrity or availability. The vulnerability requires high privileges (realm administrator role) and no user interaction.
Mitigation Recommendations
Red Hat has released Keycloak 26.4.13 packages and container images addressing multiple security issues including CVE-2026-9083. Although the advisories do not explicitly confirm a patch for this specific vulnerability, applying the Keycloak 26.4.13 update is recommended. Before updating, back up all existing installations, configurations, and databases. Monitor Red Hat's official advisories for confirmation of patch status and further remediation guidance. No alternative mitigations or workarounds are specified.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- redhat
- Date Reserved
- 2026-05-20T14:11:59.940Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-9083","vendor":"Red Hat"}]
Threat ID: 6a3d5b514853345fc13372c9
Added to database: 06/25/2026, 16:46:09 UTC
Last enriched: 07/02/2026, 22:42:19 UTC
Last updated: 08/09/2026, 12:41:12 UTC
Views: 74
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.