Description
A flaw was found in the Keycloak Admin REST API, which is used to manage security realms and clients. The issue occurs when the system processes requests for rotated client secrets that are stored in a secure vault. Due to improper boundary enforcement, a delegated administrator with view-only permissions can retrieve the actual resolved secret instead of the vault placeholder, leading to the exposure of sensitive credentials.
Published: 2026-07-24
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the Keycloak Admin REST API allows a delegated administrator with view‑only permissions to obtain the real rotated client secret from a secure vault instead of the expected placeholder. This leads to the disclosure of sensitive credentials stored as client secrets, exposing services to impersonation or unauthorized access.

Affected Systems

The vulnerability impacts Red Hat Build of Keycloak, Red Hat Data Grid 8, Red Hat JBoss Enterprise Application Platform Expansion Pack, and Red Hat Single Sign‑On 7. No specific version details are listed, so all supported releases are potentially affected.

Risk and Exploitability

The CVSS score of 5.5 indicates moderate severity for data exposure. The EPSS score of < 1% shows a very low likelihood of exploitation, and the issue is not cataloged in CISA KEV. Exploitation requires access to the Keycloak Admin REST API and a delegated administrator account with view‑only rights; the lack of a public exploit and low probability mitigate immediate impact but warrant review of exposed credentials and role configuration.

Generated by OpenCVE AI on August 4, 2026 at 15:06 UTC.

Remediation

Vendor Workaround

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.


OpenCVE Recommended Actions

  • Apply the vendor’s security patch for Keycloak and related products when it becomes available.
  • Restrict delegated administrator accounts to remove view‑only privileges for client secrets.
  • Limit exposure of the Keycloak Admin REST API to trusted networks or specific IP ranges.
  • No official workaround is available; monitor for vendor updates.

Generated by OpenCVE AI on August 4, 2026 at 15:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Redhat data Grid
Redhat jboss Enterprise Application Platform Expansion Pack
Vendors & Products Redhat data Grid
Redhat jboss Enterprise Application Platform Expansion Pack

Sat, 25 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Fri, 24 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Description A flaw was found in the Keycloak Admin REST API, which is used to manage security realms and clients. The issue occurs when the system processes requests for rotated client secrets that are stored in a secure vault. Due to improper boundary enforcement, a delegated administrator with view-only permissions can retrieve the actual resolved secret instead of the vault placeholder, leading to the exposure of sensitive credentials.
Title Keycloak-services: keycloak-services: vault-resolved rotated client secrets leaked via admin rest api
First Time appeared Redhat
Redhat build Keycloak
Redhat jboss Data Grid
Redhat jbosseapxp
Redhat red Hat Single Sign On
Weaknesses CWE-200
CPEs cpe:/a:redhat:build_keycloak:
cpe:/a:redhat:jboss_data_grid:8
cpe:/a:redhat:jbosseapxp
cpe:/a:redhat:red_hat_single_sign_on:7
Vendors & Products Redhat
Redhat build Keycloak
Redhat jboss Data Grid
Redhat jbosseapxp
Redhat red Hat Single Sign On
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N'}


Subscriptions

Redhat Build Keycloak Build Of Keycloak Data Grid Jboss Data Grid Jboss Enterprise Application Platform Expansion Pack Jbosseapxp Red Hat Single Sign On
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-07-24T19:54:56.056Z

Reserved: 2026-07-24T13:25:29.276Z

Link: CVE-2026-17048

cve-icon Vulnrichment

Updated: 2026-07-24T19:54:49.066Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-24T14:16:26.493

Modified: 2026-08-10T12:35:45.157

Link: CVE-2026-17048

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-07-21T10:47:21Z

Links: CVE-2026-17048 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T15:15:04Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor