Path traversal in Keycloak - CVE-2026-9083

 

Path traversal in Keycloak - CVE-2026-9083

Published: June 29, 2026


Vulnerability identifier: #VU135696
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-9083
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to path traversal in the key provider component creation keystore parameter when creating a key provider component. A remote privileged user can submit an arbitrary filesystem path as a keystore parameter to disclose sensitive information.

The issue allows probing arbitrary filesystem paths to determine which files exist and are readable by the Keycloak process.


Affected software

Keycloak

How to mitigate CVE-2026-9083

Install security update from vendor's website.

Keycloak - update to 26.6.4

External References

Related Security Bulletins