Impact
A flaw in the Keycloak Admin REST API allows a delegated administrator with view‑only permissions to obtain the real rotated client secret from a secure vault instead of the expected placeholder. This leads to the disclosure of sensitive credentials stored as client secrets, exposing services to impersonation or unauthorized access.
Affected Systems
The vulnerability impacts Red Hat Build of Keycloak, Red Hat Data Grid 8, Red Hat JBoss Enterprise Application Platform Expansion Pack, and Red Hat Single Sign‑On 7. No specific version details are listed, so all supported releases are potentially affected.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity for data exposure. The EPSS score of < 1% shows a very low likelihood of exploitation, and the issue is not cataloged in CISA KEV. Exploitation requires access to the Keycloak Admin REST API and a delegated administrator account with view‑only rights; the lack of a public exploit and low probability mitigate immediate impact but warrant review of exposed credentials and role configuration.
OpenCVE Enrichment