CVE detail
CVE-2026-9083
A flaw was found in Keycloak. A realm administrator with the "manage-realm" role can exploit this vulnerability by submitting an arbitrary filesystem path as a keystore parameter when creating a key provider component. This allows the administrator to probe arbitrary filesystem paths, determining which files exist and are readable by the Keycloak process. This information disclosure could be used to identify high-value targets for follow-on attacks.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 19.5 · diversity 10.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
6 source links · newest first
- https://bugzilla.redhat.com/show_bug.cgi?id=2480168bugzilla.redhat.com
No excerpt available.
Exploitbugzilla.redhat.comJun 25, 2026, 5:17 PM - https://access.redhat.com/security/cve/CVE-2026-9083access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 25, 2026, 5:17 PM - https://access.redhat.com/errata/RHSA-2026:30084access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 25, 2026, 5:17 PM - https://access.redhat.com/errata/RHSA-2026:30083access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 25, 2026, 5:17 PM - https://access.redhat.com/errata/RHSA-2026:30050access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 25, 2026, 5:17 PM - https://access.redhat.com/errata/RHSA-2026:30049access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 25, 2026, 5:17 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2024-1132CVSS 8.1 · High
A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. This issue could allow an attacker to construct a malicious request to bypass valida…
- CVE-2026-43749CVSS 7.8 · High
A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6.…
- CVE-2026-43723CVSS 7.8 · High
A path handling issue was addressed with improved validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26…
- CVE-2026-65921CVSS 8.8 · High
A path validation weakness in archive extraction/write handling allows entries with traversal sequences to be written outside the intended build artifacts location.
- CVE-2026-45623CVSS 7.5 · High
PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. In versions 8.5.11 and prior, the PreviousMap…
- CVE-2026-66397CVSS 8.6 · High
phpMyFAQ before 4.1.6 fails to validate path traversal sequences in the existing_image field during category updates, allowing authenticated attackers to delete arbitrary files by…