---
id: CVE-2026-19729
title: >-
  A flaw was found in the key provider component of the keycloak-services
  library, which is the core engine for the Red Hat Build of Keycloak
summary: >-
  A flaw was found in the key provider component of the keycloak-services
  library, which is the core engine for the Red Hat Build of Keycloak. The issue
  occurs because a previous fix for path probing was incomplete, allowing a
  realm admini…
severity: medium
cvss: 4.9
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-22
vendor: Red Hat
product: keycloak-rhel9-container
affected:
  - keycloak-rhel9-container (all versions)
  - keycloak-rhel9-operator-container (all versions)
  - rhbk/keycloak-operator-bundle (all versions)
  - keycloak-services
  - rhbk-openshift-rhel9/rhbk-openshift-rhel9
  - keycloak-rhel9-container (all versions)
  - keycloak-rhel9-operator-bundle-container (all versions)
  - keycloak-rhel9-operator-container (all versions)
  - keycloak-services
  - rhbk-openshift-rhel9/rhbk-openshift-rhel9
  - keycloak-services
patched:
  - build_of_keycloak 26.4
  - build_of_keycloak 26.4.16
  - build_of_keycloak 26.6.7
published: '2026-09-09'
updated: '2026-09-16'
sourceUpdated: '2026-09-16T19:17:10.540'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-19729'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2026:68276'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:68277'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:68278'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:68280'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2026-19729'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2515294'
    label: secalert@redhat.com
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-19729.json
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-19729'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-19729'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
epss: 0.00484
epssPercentile: 0.39044
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-09T17:59:10.749049Z'
ingestedAt: '2026-09-09T08:04:11.992Z'
---

## Overview

A flaw was found in the key provider component of the keycloak-services library, which is the core engine for the Red Hat Build of Keycloak. The issue occurs because a previous fix for path probing was incomplete, allowing a realm administrator to still submit arbitrary filesystem paths as keystore parameters. This can be used to determine the existence and readability of files on the server, potentially exposing sensitive system information.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **Red Hat VEX** · Moderate · affected: Red Hat Build of Keycloak · no fix planned: Red Hat Build of Keycloak · updated 2026-09-09 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-19729.json)
- **RHSA-2026:68276** · Red Hat · fixed in: Red Hat build of Keycloak 26.4 · released 2026-09-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:68276)
- **RHSA-2026:68280** · Red Hat · fixed in: Red Hat build of Keycloak 26.4.16 · released 2026-09-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:68280)
- **RHSA-2026:68278** · Red Hat · fixed in: Red Hat build of Keycloak 26.6.7 · released 2026-09-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:68278)
- **RHSA-2026:68277** · Red Hat · fixed in: Red Hat build of Keycloak 26.6 · released 2026-09-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:68277)
