A security vulnerability has been identified that allows admin users to access sensitive server environment variables and system properties through user-configurable URLs. Specifically, when configuring backchannel logout URLs or admin URLs, admin users can include placeholders like ${env.VARNAME} or ${PROPNAME}. The server replaces these placeholders with the actual values of environment variables or system properties during URL processing.
This issue has been addressed in the following products: RHBK 26.0.8 Via RHSA-2025:0300 https://access.redhat.com/errata/RHSA-2025:0300
This issue has been addressed in the following products: Red Hat build of Keycloak 26.0 Via RHSA-2025:0299 https://access.redhat.com/errata/RHSA-2025:0299