Keycloak
26.5.1SecurityJan 14, 2026
Keycloak 26.5.1 is a maintenance release with a security fix in the `Organization` feature. It also contains correctness fixes, a performance improvement, and changes to HTTP responses and realm administration.
Check if affected (1)
securityThe
Organizationfeature account-name exposure fixApplies if you use the
Organizationfeature.The
Organizationfeature no longer exposes and automatically fills the account name in the user/password form. The fix ships in Keycloak 26.5.1.
All 13 other recorded changesfixes 10 · value changes 2 · additions 1
fixes (10)
- 403 Forbidden when assigning realm-management client roles despite FGAP disabled (regression in 26.4.0+)
- Create Realm button is missing when user has create-realm role
- Admin UI: slow response time listing second user page
- Bug in JWTClientAuthenticator and JWTClientSecretAuthenticator causes NPE
- Enable visibility of Role Mapping tab for users with view-users role
- Failed upgrade to 26.4.7 - sql generated for manual database upgrade contains invalid statements
- Realm-level admininistrators can no longer use Admin Console since 26.3.0 (UI fails to render)
- Failure when decrypting SAML Response since 26.5.0
- Upgrade to 26.5.0 failing due to FK_ORG_INVITATION_ORG constraint
- UI Bug: WebAuthn passkey list is broken in keycloak v2 theme
value changes (2)
- x-robots HTTP header missing for static Keycloak resources, and REST endpoint responses
- Performance improvement: Missing indexes on BROKER_LINK table columns
additions (1)
- Allow full managing of realms from master realm without global admin role
Add Keycloak to your stack
A weekly email arrives when a release needs action. Like the security patches in this release.