CVE detail
CVE-2026-9083
A flaw was found in Keycloak. A realm administrator with the "manage-realm" role can exploit this vulnerability by submitting an arbitrary filesystem path as a keystore parameter when creating a key provider component. This allows the administrator to probe arbitrary filesystem paths, determining which files exist and are readable by the Keycloak process. This information disclosure could be used to identify high-value targets for follow-on attacks.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 19.5 · diversity 10.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
6 source links · newest first
- https://bugzilla.redhat.com/show_bug.cgi?id=2480168bugzilla.redhat.com
No excerpt available.
Exploitbugzilla.redhat.comJun 25, 2026, 5:17 PM - https://access.redhat.com/security/cve/CVE-2026-9083access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 25, 2026, 5:17 PM - https://access.redhat.com/errata/RHSA-2026:30084access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 25, 2026, 5:17 PM - https://access.redhat.com/errata/RHSA-2026:30083access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 25, 2026, 5:17 PM - https://access.redhat.com/errata/RHSA-2026:30050access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 25, 2026, 5:17 PM - https://access.redhat.com/errata/RHSA-2026:30049access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 25, 2026, 5:17 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2024-1132CVSS 8.1 · High
A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. This issue could allow an attacker to construct a malicious request to bypass valida…
- CVE-2026-66397CVSS 8.6 · High
phpMyFAQ before 4.1.6 fails to validate path traversal sequences in the existing_image field during category updates, allowing authenticated attackers to delete arbitrary files by…
- CVE-2026-66476CVSS 4.9 · Medium
Administrator Arbitrary File Deletion in Easy Digital Downloads <= 3.6.9 versions.
- CVE-2026-66050CVSS 8.7 · High
NitroShare Desktop through 0.3.4 contains a path traversal vulnerability in its LAN file transfer server that allows unauthenticated attackers on the same network to write arbitra…
- CVE-2026-65436CVSS 6.8 · Medium
Editor Arbitrary File Deletion in Kirki <= 6.0.13 versions.
- CVE-2026-65878CVSS 8.3 · High
Joomla Extension - joomshaper.com - Authenticated arbitrary file delete in SP Page Builder < 6.7.1- Improper path validation and ACL checks lead to a file deletion vector in the m…