---
id: CVE-2026-16104
title: >-
  A flaw was found in the authentication configuration endpoint of the
  keycloak-services component, which is the core engine for Red Hat Build of
  Keycloak identity and access management
summary: >-
  A flaw was found in the authentication configuration endpoint of the
  keycloak-services component, which is the core engine for Red Hat Build of
  Keycloak identity and access management. The issue occurs because the system
  fails to mask se…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-212
  - CWE-522
vendor: redhat
product: build_of_keycloak
affected:
  - build_of_keycloak
patched:
  - build_of_keycloak 26.6.7
published: '2026-07-17'
updated: '2026-09-16'
sourceUpdated: '2026-09-16T19:17:07.513'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-16104'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2026:68277'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:68278'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2026-16104'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2501737'
    label: secalert@redhat.com
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-16104.json
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-16104'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-16104'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
epss: 0.00455
epssPercentile: 0.3686
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-07-17T17:24:30.498422Z'
ingestedAt: '2026-08-31T11:07:13.998Z'
---

## Overview

A flaw was found in the authentication configuration endpoint of the keycloak-services component, which is the core engine for Red Hat Build of Keycloak identity and access management. The issue occurs because the system fails to mask sensitive configuration values, such as reCAPTCHA secret keys, when they are requested by administrators with view-only permissions. This can lead to the exposure of third-party service credentials to unauthorized personnel or through administrative logs.

## Affected

- `build_of_keycloak`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **RHSA-2026:68278** · Red Hat · fixed in: Red Hat build of Keycloak 26.6.7 · released 2026-09-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:68278)
- **RHSA-2026:68277** · Red Hat · fixed in: Red Hat build of Keycloak 26.6 · released 2026-09-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:68277)
