Description
A flaw was found in the authentication configuration endpoint of the keycloak-services component, which is the core engine for Red Hat Build of Keycloak identity and access management. The issue occurs because the system fails to mask sensitive configuration values, such as reCAPTCHA secret keys, when they are requested by administrators with view-only permissions. This can lead to the exposure of third-party service credentials to unauthorized personnel or through administrative logs.
Published: 2026-07-17
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw in the authentication configuration endpoint of the keycloak-services component causes the system to expose sensitive configuration values, such as reCAPTCHA secret keys, when accessed by administrators with view-only permissions. This allows an attacker with view-only admin rights to read third‑party service credentials or see them in administrative logs, thereby compromising confidentiality. The vulnerability does not provide direct code execution or privilege escalation, but it enables leakage of credentials that could be used to compromise external services or downstream systems.

Affected Systems

Products affected include Red Hat Build of Keycloak, Red Hat Data Grid 8, Red Hat JBoss Enterprise Application Platform Expansion Pack, and Red Hat Single Sign‑On 7. No specific version information is provided in the current data.

Risk and Exploitability

The CVSS score of 4.3 indicates a low severity, and the EPSS score of < 1% suggests a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is that an adversary must already possess view‑only administrator privileges to read the configuration endpoint; no additional conditions or exploits are required. Consequently, the overall risk is limited, but the exposure of secret keys remains a serious concern if those keys grant access to critical third‑party services. The vendor has indicated that no workaround is available.

Generated by OpenCVE AI on July 31, 2026 at 00:02 UTC.

Remediation

Vendor Workaround

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.


OpenCVE Recommended Actions

  • Replace or mask the exposed reCAPTCHA secret keys so they are no longer returned by the configuration endpoint.
  • Revoke or limit view‑only administrator permissions for accessing the authentication configuration endpoint so that only trusted operators can view sensitive settings.
  • When a vendor patch or fix is released, apply it immediately. Until then, monitor administrative logs for any inadvertent disclosure of secret keys.

Generated by OpenCVE AI on July 31, 2026 at 00:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Redhat build Of Keycloak
Redhat data Grid
Redhat jboss Enterprise Application Platform Expansion Pack
Redhat single Sign-on
Vendors & Products Redhat build Of Keycloak
Redhat data Grid
Redhat jboss Enterprise Application Platform Expansion Pack
Redhat single Sign-on

Sat, 18 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Fri, 17 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-522
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 17 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Description A flaw was found in the authentication configuration endpoint of the keycloak-services component, which is the core engine for Red Hat Build of Keycloak identity and access management. The issue occurs because the system fails to mask sensitive configuration values, such as reCAPTCHA secret keys, when they are requested by administrators with view-only permissions. This can lead to the exposure of third-party service credentials to unauthorized personnel or through administrative logs.
Title Keycloak-services: keycloak-services: authenticator config endpoint exposes raw recaptcha secrets to view-only admins
First Time appeared Redhat
Redhat build Keycloak
Redhat jboss Data Grid
Redhat jbosseapxp
Redhat red Hat Single Sign On
CPEs cpe:/a:redhat:build_keycloak:
cpe:/a:redhat:jboss_data_grid:8
cpe:/a:redhat:jbosseapxp
cpe:/a:redhat:red_hat_single_sign_on:7
Vendors & Products Redhat
Redhat build Keycloak
Redhat jboss Data Grid
Redhat jbosseapxp
Redhat red Hat Single Sign On
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Redhat Build Keycloak Build Of Keycloak Data Grid Jboss Data Grid Jboss Enterprise Application Platform Expansion Pack Jbosseapxp Red Hat Single Sign On Single Sign-on
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-07-17T17:24:34.155Z

Reserved: 2026-07-17T14:48:32.086Z

Link: CVE-2026-16104

cve-icon Vulnrichment

Updated: 2026-07-17T17:24:25.288Z

cve-icon NVD

No data.

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-07-15T13:25:50Z

Links: CVE-2026-16104 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T00:15:05Z

Weaknesses
  • CWE-522

    Insufficiently Protected Credentials