Medium severity5.5NVD Advisory· Published Jul 24, 2026· Updated Aug 19, 2026
CVE-2026-17048
CVE-2026-17048
Description
A flaw was found in the Keycloak Admin REST API, which is used to manage security realms and clients. The issue occurs when the system processes requests for rotated client secrets that are stored in a secure vault. Due to improper boundary enforcement, a delegated administrator with view-only permissions can retrieve the actual resolved secret instead of the vault placeholder, leading to the exposure of sensitive credentials.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- cpe:2.3:a:redhat:build_of_keycloak:-:*:*:*:-:*:*:*
Patches
Vulnerability mechanics
References
4- access.redhat.com/security/cve/CVE-2026-17048nvdVendor Advisory
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingVendor Advisory
- access.redhat.com/errata/RHSA-2026:56523nvd
- access.redhat.com/errata/RHSA-2026:56524nvd
News mentions
0No linked articles in our index yet.