Keycloak Admin REST API: View-Only Admins Can Leak Client Secrets
CVE-2026-17048 Published on July 24, 2026
Keycloak-services: keycloak-services: vault-resolved rotated client secrets leaked via admin rest api
A flaw was found in the Keycloak Admin REST API, which is used to manage security realms and clients. The issue occurs when the system processes requests for rotated client secrets that are stored in a secure vault. Due to improper boundary enforcement, a delegated administrator with view-only permissions can retrieve the actual resolved secret instead of the vault placeholder, leading to the exposure of sensitive credentials.
Vulnerability Analysis
CVE-2026-17048 is exploitable with network access, and requires user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality, with no impact on integrity, and no impact on availability.
Timeline
Reported to Red Hat.
Made public.
Weakness Type
What is an Information Disclosure Vulnerability?
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CVE-2026-17048 has been classified to as an Information Disclosure vulnerability or weakness.
Products Associated with CVE-2026-17048
Want to know whenever a new CVE is published for Red Hat products? stack.watch will email you.