Path traversal in Keycloak - CVE-2026-9083
Published: June 29, 2026
Keycloak
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to path traversal in the key provider component creation keystore parameter when creating a key provider component. A remote privileged user can submit an arbitrary filesystem path as a keystore parameter to disclose sensitive information.
The issue allows probing arbitrary filesystem paths to determine which files exist and are readable by the Keycloak process.