Improper Removal of Sensitive Information Before Storage or Transfer in Keycloak - CVE-2026-16104
Published: July 17, 2026 / Updated: September 5, 2026
Vulnerability details
The vulnerability allows a remote user to disclose third-party service credentials.
The vulnerability exists due to improper removal of sensitive information before transfer in the authentication configuration endpoint of the keycloak-services component when handling requests for configuration values. A remote user can request authentication configuration values to disclose third-party service credentials.
Exploitation requires an administrator account with view-only permissions, and exposed values may include reCAPTCHA secret keys.