What is CVE-2026-16100?
A flaw in Keycloak's user-event metrics recording allows authenticated users to exploit Prometheus metric labels, which capture raw error messages containing user-supplied input like nonexistent client IDs. This could lead to sensitive information disclosure when metrics are enabled.
Azərbaycanca: Keycloak-da aktiv edilmiş Prometheus metrikaları zamanı baş verən boşluqdur. Səhv mesajları istifadəçi tərəfindən daxil edilən məlumatları (məsələn, mövcud olmayan client ID) etiket kimi qeyd etdiyi üçün autentifikasiya olunmuş istifadəçi həssas məlumatları əldə edə bilər. Təhlükəsizlik üçün metrik qeydiyyatında filtirləmə tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
Is authentication required to exploit CVE-2026-16100?
Yes, an attacker must be an authenticated user to exploit this flaw.
What type of information can be disclosed due to CVE-2026-16100?
Sensitive information can be disclosed because Prometheus metrics record raw error messages containing user-supplied input, such as nonexistent client IDs, as labels when metrics are enabled.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.