Back to overview

CVE-2026-17048

MEDIUM
5.5
CVSS 3.1
Description
A flaw was found in the Keycloak Admin REST API, which is used to manage security realms and clients. The issue occurs when the system processes requests for rotated client secrets that are stored in a secure vault. Due to improper boundary enforcement, a delegated administrator with view-only permissions can retrieve the actual resolved secret instead of the vault placeholder, leading to the exposure of sensitive credentials.

Metadata

CVE ID
CVE-2026-17048
State
PUBLISHED
Assigner
redhat
Reserved
2026-07-24 13:25 UTC
Published
2026-07-24 13:41 UTC
Last updated
2026-07-24 13:41 UTC
Primary CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
Vendor / Product
Red Hat / Red Hat Build of Keycloak
Sources
cve.org  ·  NVD

Severity & Metrics

5.5 MEDIUM CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N
Affected products (6)
VendorProductPlatformVersions
Red Hat Red Hat Build of Keycloak
Red Hat Red Hat Build of Keycloak
Red Hat Red Hat Build of Keycloak
Red Hat Red Hat Data Grid 8
Red Hat Red Hat JBoss Enterprise Application Platform Expansion Pack
Red Hat Red Hat Single Sign-On 7
Weakness (CWE)
CWESourceDescription
CWE-200 cna Exposure of Sensitive Information to an Unauthorized Actor
CVSS scores (1)
ScoreSeverityVersionSourceVector
5.5 MEDIUM 3.1 cna CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N
Back to overview