Red HatCVE-2026-16104
Red Hat Data Grid 8: weakly protected credentials
Medium4.3CVE-2026-16104 · Published Jul 17, 2026 · updated Sep 16, 2026
A flaw was found in the authentication configuration endpoint of the keycloak-services component, which is the core engine for Red Hat Build of Keycloak identity and access management. The issue occurs because the system fails to mask sensitive configuration values, such as reCAPTCHA secret keys, when they are requested by administrators with view-only permissions. This can lead to the exposure of third-party service credentials to unauthorized personnel or through administrative logs.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Red Hat Data Grid 8 Product | all versions | No fix yet |
| Red Hat JBoss Enterprise Application Platform Expansion Pack Product | all versions | No fix yet |
| Red Hat Single Sign-On 7 Product | all versions | No fix yet |
| Red Hat build of Keycloak 26.6.7 Product | all versions | No fix yet |
| all versions | No fix yet | |
| all versions | No fix yet |
Details and references
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 17 | Red Hat xdgmime: heap buffer overflow | High7.1 | No fix yet |
| Jul 17 | Red Hat Data Grid 8: untrusted input in a security decision | Medium5.4 | No fix yet |
| Jul 17 | Red Hat keycloak-services: attacker could obtain access | Medium4.3 | No fix yet |
| Jul 17 | Red Hat admin REST API of Keycloak: missing authorization | Medium4.9 | No fix yet |
| Jul 17 | Red Hat default-groups REST endpoint: information disclosure | Medium4.3 | No fix yet |
| Jul 17 | Red Hat keycloak-services: session fixation | Medium5.4 | No fix yet |