CVE-2026-17048
CVE-2026-17048 is a medium-severity vulnerability in Redhat Build Of Keycloak with a CVSS 3.x base score of 5.5. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-200.
Key facts
- Severity: Medium (CVSS 3.x base score 5.5)
- EPSS exploit prediction: 0% (16th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-200
- Affected product: Redhat Build Of Keycloak
- Published:
- Last modified:
Description
A flaw was found in the Keycloak Admin REST API, which is used to manage security realms and clients. The issue occurs when the system processes requests for rotated client secrets that are stored in a secure vault. Due to improper boundary enforcement, a delegated administrator with view-only permissions can retrieve the actual resolved secret instead of the vault placeholder, leading to the exposure of sensitive credentials.
Frequently asked questions
- What is CVE-2026-17048?
- A flaw was found in the Keycloak Admin REST API, which is used to manage security realms and clients. The issue occurs when the system processes requests for rotated client secrets that are stored in a secure vault. Due to improper boundary enforcement, a delegated administrator with view-only permissions can retrieve the actual resolved secret instead of the vault placeholder, leading to the exposure of sensitive credentials.
- How severe is CVE-2026-17048?
- CVE-2026-17048 has a CVSS 3.x base score of 5.5, rated medium severity. It is exploitable over network with low attack complexity, requires high privileges and no user interaction. Impact on confidentiality is high, integrity low, and availability none.
- Is CVE-2026-17048 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (16th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-17048?
- CVE-2026-17048 affects Redhat Build Of Keycloak. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2026-17048?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2026-17048 published?
- CVE-2026-17048 was published on 2026-07-24 and last updated on 2026-08-19.
References
- https://access.redhat.com/errata/RHSA-2026:56523
- https://access.redhat.com/errata/RHSA-2026:56524
- https://access.redhat.com/security/cve/CVE-2026-17048
- https://bugzilla.redhat.com/show_bug.cgi?id=2506743
Affected products (1)
- cpe:2.3:a:redhat:build_of_keycloak:-:*:*:*:-:*:*:*
More vulnerabilities in Redhat Build Of Keycloak
- CVE-2026-15572 — High (CVSS 8.8): A flaw was found in Keycloak's Dynamic Client Registration (DCR) security policy management. The "Allowed Protocol…
- CVE-2026-3047 — High (CVSS 8.8): A flaw was found in org.keycloak.broker.saml. When a disabled Security Assertion Markup Language (SAML) client is…
- CVE-2026-16102 — High (CVSS 8.1): A flaw was found in the Dynamic Client Registration (DCR) component of Keycloak, an identity and access management…
- CVE-2026-15573 — High (CVSS 8.1): A flaw was found in Keycloak's Authorization Services. The component responsible for matching request paths to security…
- CVE-2026-1609 — High (CVSS 8.1): A flaw was found in Keycloak. When the JSON Web Token (JWT) authorization grant preview feature is enabled and a user…
- CVE-2026-11800 — High (CVSS 8.1): A flaw was found in Keycloak. This JWT algorithm confusion vulnerability in the JWT Authorization Grant flow allows an…
All CVEs affecting Redhat Build Of Keycloak →
Other CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) vulnerabilities
- CVE-2026-27604 — Critical (CVSS 10.0): FOSSBilling is a free, open-source billing and client management system. Starting in version 0.5.4 and prior to version…
- CVE-2026-40965 — Critical (CVSS 10.0): Cloud Foundry UAA versions v76.12.0 through v78.12.0 are vulnerable to a private key exposure. The server contains a…
- CVE-2026-42826 — Critical (CVSS 10.0): Exposure of sensitive information to an unauthorized actor in Azure DevOps allows an unauthorized attacker to disclose…
- CVE-2025-29270 — Critical (CVSS 10.0): Incorrect access control in the realtime.cgi endpoint of Deep Sea Electronics devices DSE855 v1.1.0 to v1.1.26 allows…
- CVE-2025-61481 — Critical (CVSS 10.0): An issue in MikroTik RouterOS v.7.14.2 and SwOS v.2.18 exposes the WebFig management interface over cleartext HTTP by…
- CVE-2025-53624 — Critical (CVSS 10.0): The Docusaurus gists plugin adds a page to your Docusaurus instance, displaying all public gists of a GitHub user.…
Browse all CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) vulnerabilities →