Red HatCVE-2026-17048
Red Hat Keycloak Admin REST API: information disclosure
Medium5.5CVE-2026-17048 · Published Jul 24, 2026 · updated Aug 19, 2026
A flaw was found in the Keycloak Admin REST API, which is used to manage security realms and clients. The issue occurs when the system processes requests for rotated client secrets that are stored in a secure vault. Due to improper boundary enforcement, a delegated administrator with view-only permissions can retrieve the actual resolved secret instead of the vault placeholder, leading to the exposure of sensitive credentials.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Red Hat Build of Keycloak Product | all versions | No fix yet |
| Red Hat Data Grid 8 Product | all versions | No fix yet |
| Red Hat JBoss Enterprise Application Platform Expansion Pack Product | all versions | No fix yet |
| Red Hat Single Sign-On 7 Product | all versions | No fix yet |
| Red Hat build of Keycloak 26.6.6 Product | all versions | No fix yet |
| all versions | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-200
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 24 | Red Hat libsoup: request smuggling | Medium5.4 | No fix yet |
| Jul 24 | Red Hat libsoup: information disclosure | Medium6.5 | No fix yet |
| Jul 24 | Red Hat libsoup. An unsigned integer underflow: integer overflow | Medium6.5 | No fix yet |
| Jul 24 | A flaw was found in the cluster-proxy service-proxy component used in Red Hat... | High8.5 | No fix yet |
| Jul 24 | Red Hat pki-core: improper authorization | Low3.1 | No fix yet |
| Jul 24 | Red Hat role-users endpoint: insecure direct object reference | Medium6.5 | No fix yet |