What is CVE-2026-17048?
A flaw in the Keycloak Admin REST API involves improper boundary enforcement when processing requests for rotated client secrets stored in a secure vault. A delegated administrator with view-only permissions could potentially gain unauthorized access to sensitive information. Upgrading Keycloak to the latest version is strongly recommended.
Azərbaycanca: Keycloak Admin REST API-də aşkar edilmiş bu boşluq, təhlükəsiz anbarda saxlanılan rotasiya edilmiş müştəri sirrlərinin sorğularını emal edərkən baş verir. Yalnız oxuma icazəsi olan səlahiyyətli bir inzibatçı, sərhəd yoxlamasının düzgün aparılmaması səbəbindən gizli məlumatlara potensial olaraq icazəsiz giriş əldə edə bilər. Təcili olaraq Keycloak-ı ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-863
FAQ2
Which privileged user profile is affected by the CVE-2026-17048 vulnerability discovered in the Keycloak Admin REST API?
Delegated administrators with view-only permissions can potentially be affected by this flaw.
Where are the rotated client secrets stored that are related to the CVE-2026-17048 flaw?
The flaw occurs when processing requests for rotated client secrets stored in a secure vault.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.