<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 00:34:14 +0000</lastBuildDate>
    <item>
      <title>BIT-keycloak-2026-9083 — Keycloak: keycloak: information disclosure through arbitrary filesystem path probing</title>
      <link>https://cve.radiocsirt.org/vuln/bit-keycloak-2026-9083</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: keycloak&lt;/p&gt;
&lt;p&gt;A flaw was found in Keycloak. A realm administrator with the &amp;#34;manage-realm&amp;#34; role can exploit this vulnerability by submitting an arbitrary filesystem path as a keystore parameter when creating a key provider component. This allows the administrator to probe arbitrary filesystem paths, determining which files exist and are readable by the Keycloak process. This information disclosure could be used to identify high-value targets for follow-on attacks.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: keycloak&lt;/p&gt;
&lt;p&gt;A flaw was found in Keycloak. A realm administrator with the &amp;#34;manage-realm&amp;#34; role can exploit this vulnerability by submitting an arbitrary filesystem path as a keystore parameter when creating a key provider component. This allows the administrator to probe arbitrary filesystem paths, determining which files exist and are readable by the Keycloak process. This information disclosure could be used to identify high-value targets for follow-on attacks.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-keycloak-2026-9083</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0815 — De multiples vulnérabilités ont été découvertes dans KeyCloak. Certaines d'entre elles permettent à un attaquant de pro…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0815</link>
      <description>certfr-2026-avi-0815</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0815</guid>
    </item>
    <item>
      <title>EUVD-2026-330491</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-330491</link>
      <description>EUVD-2026-330491</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-330491</guid>
    </item>
    <item>
      <title>fkie_cve-2026-9083</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-9083</link>
      <description>&lt;p&gt;A flaw was found in Keycloak. A realm administrator with the &amp;#34;manage-realm&amp;#34; role can exploit this vulnerability by submitting an arbitrary filesystem path as a keystore parameter when creating a key provider component. This allows the administrator to probe arbitrary filesystem paths, determining which files exist and are readable by the Keycloak process. This information disclosure could be used to identify high-value targets for follow-on attacks.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in Keycloak. A realm administrator with the &amp;#34;manage-realm&amp;#34; role can exploit this vulnerability by submitting an arbitrary filesystem path as a keystore parameter when creating a key provider component. This allows the administrator to probe arbitrary filesystem paths, determining which files exist and are readable by the Keycloak process. This information disclosure could be used to identify high-value targets for follow-on attacks.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-9083</guid>
    </item>
    <item>
      <title>GHSA-7pm9-g8jh-3m74</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-7pm9-g8jh-3m74</link>
      <description>&lt;p&gt;A flaw was found in Keycloak. A realm administrator with the &amp;#34;manage-realm&amp;#34; role can exploit this vulnerability by submitting an arbitrary filesystem path as a keystore parameter when creating a key provider component. This allows the administrator to probe arbitrary filesystem paths, determining which files exist and are readable by the Keycloak process. This information disclosure could be used to identify high-value targets for follow-on attacks.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in Keycloak. A realm administrator with the &amp;#34;manage-realm&amp;#34; role can exploit this vulnerability by submitting an arbitrary filesystem path as a keystore parameter when creating a key provider component. This allows the administrator to probe arbitrary filesystem paths, determining which files exist and are readable by the Keycloak process. This information disclosure could be used to identify high-value targets for follow-on attacks.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-7pm9-g8jh-3m74</guid>
    </item>
    <item>
      <title>RHSA-2026:30049 — Red Hat Security Advisory: Red Hat build of Keycloak 26.4.13 Security Update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:30049</link>
      <description>&lt;p&gt;org.keycloak.protocol.oidc.grants: org.keycloak.services.managers: Keycloak: Server-Side Request Forgery via OIDC token endpoint manipulation eclipse-vertx/vert.x: eclipse-vertx/vert.x: Denial of Service via TLS handshake with wildcard server name org.keycloak.keycloak-services: Improper Access Control on Keycloak Server when the account Account API feature is disabled keycloak: org.keycloak/keycloak-services: Keycloak: Policy bypass during WebAuthn credential registration via client-side JavaScript manipulation org.keycloak/keycloak-services: keycloak: org.keycloak.protocol.oidc: Security flaw in org.keycloak/keycloak-services keycloak: Keycloak: Information disclosure through arbitrary filesystem path probing keycloak: Keycloak: Cross-site scripting (XSS) via case-insensitive URI validation bypass keycloak: Cross-Session Email Verification Proof Not Bound to Upstream Identity in First-Broker-Login keycloak: Keycloak: Information disclosure due to user profile permission bypass keycloak: Group-Admin Escalation to Realm-Admin keycloak: Keycloak: Privilege escalation due to oversized subject_token JWT keycloak: Keycloak: Attacker can re-enable and take over disabled clients via Registration Access Token keycloak-rhel9: Organization Data Leak After Feature Disabled in Keycloak keycloak: Keycloak: Security restriction bypass allows unauthorized ROPC token acquisition keycloak: Keycloak: Information disclosure via SAML ECP endpoint keycloak: Keycloak: Privilege escalation via im…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;org.keycloak.protocol.oidc.grants: org.keycloak.services.managers: Keycloak: Server-Side Request Forgery via OIDC token endpoint manipulation eclipse-vertx/vert.x: eclipse-vertx/vert.x: Denial of Service via TLS handshake with wildcard server name org.keycloak.keycloak-services: Improper Access Control on Keycloak Server when the account Account API feature is disabled keycloak: org.keycloak/keycloak-services: Keycloak: Policy bypass during WebAuthn credential registration via client-side JavaScript manipulation org.keycloak/keycloak-services: keycloak: org.keycloak.protocol.oidc: Security flaw in org.keycloak/keycloak-services keycloak: Keycloak: Information disclosure through arbitrary filesystem path probing keycloak: Keycloak: Cross-site scripting (XSS) via case-insensitive URI validation bypass keycloak: Cross-Session Email Verification Proof Not Bound to Upstream Identity in First-Broker-Login keycloak: Keycloak: Information disclosure due to user profile permission bypass keycloak: Group-Admin Escalation to Realm-Admin keycloak: Keycloak: Privilege escalation due to oversized subject_token JWT keycloak: Keycloak: Attacker can re-enable and take over disabled clients via Registration Access Token keycloak-rhel9: Organization Data Leak After Feature Disabled in Keycloak keycloak: Keycloak: Security restriction bypass allows unauthorized ROPC token acquisition keycloak: Keycloak: Information disclosure via SAML ECP endpoint keycloak: Keycloak: Privilege escalation via im…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:30049</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2093 — Keycloak: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2093</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Keycloak ausnutzen, um falsche Informationen darzustellen, um Informationen offenzulegen, um einen Cross-Site Scripting Angriff durchzuführen, um Sicherheitsvorkehrungen zu umgehen, und um Dateien zu manipulieren.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Keycloak ausnutzen, um falsche Informationen darzustellen, um Informationen offenzulegen, um einen Cross-Site Scripting Angriff durchzuführen, um Sicherheitsvorkehrungen zu umgehen, und um Dateien zu manipulieren.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2093</guid>
    </item>
  </channel>
</rss>
