SEPTEMBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-16104

MEDIUM · CVSS 4.3 EPSS 0.21%

Source: NVD + CISA KEV + EPSS · Published 2026-07-17 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

A vulnerability exists in the authentication configuration endpoint of the keycloak-services component, affecting Red Hat Build of Keycloak. This flaw allows administrators with view-only permissions to access sensitive configuration values, including reCAPTCHA secret keys, potentially exposing third-party service credentials to unauthorized users or through logs. Organizations utilizing Keycloak for identity and access management should prioritize remediation to safeguard sensitive information from unauthorized access.

CVE
CVE-2026-16104
Severity
MEDIUM
CVSS
4.3
EPSS
0.21%

Original NVD Description

A flaw was found in the authentication configuration endpoint of the keycloak-services component, which is the core engine for Red Hat Build of Keycloak identity and access management. The issue occurs because the system fails to mask sensitive configuration values, such as reCAPTCHA secret keys, when they are requested by administrators with view-only permissions. This can lead to the exposure of third-party service credentials to unauthorized personnel or through administrative logs.

Related CVEs

Other vulnerabilities affecting the same vendor(s)