RATATOSKRATATOSK
Sign in

Keycloak

26.5.1Security
Jan 14, 2026

CHECK 1OTHER 13

Keycloak 26.5.1 is a maintenance release with a security fix in the `Organization` feature. It also contains correctness fixes, a performance improvement, and changes to HTTP responses and realm administration.

Check if affected (1)

  • securityThe Organization feature account-name exposure fix

    Applies if you use the Organization feature.

    The Organization feature no longer exposes and automatically fills the account name in the user/password form. The fix ships in Keycloak 26.5.1.

All 13 other recorded changesfixes 10 · value changes 2 · additions 1

fixes (10)

  • 403 Forbidden when assigning realm-management client roles despite FGAP disabled (regression in 26.4.0+)
  • Create Realm button is missing when user has create-realm role
  • Admin UI: slow response time listing second user page
  • Bug in JWTClientAuthenticator and JWTClientSecretAuthenticator causes NPE
  • Enable visibility of Role Mapping tab for users with view-users role
  • Failed upgrade to 26.4.7 - sql generated for manual database upgrade contains invalid statements
  • Realm-level admininistrators can no longer use Admin Console since 26.3.0 (UI fails to render)
  • Failure when decrypting SAML Response since 26.5.0
  • Upgrade to 26.5.0 failing due to FK_ORG_INVITATION_ORG constraint
  • UI Bug: WebAuthn passkey list is broken in keycloak v2 theme

value changes (2)

  • x-robots HTTP header missing for static Keycloak resources, and REST endpoint responses
  • Performance improvement: Missing indexes on BROKER_LINK table columns

additions (1)

  • Allow full managing of realms from master realm without global admin role
Add Keycloak to your stack

A weekly email arrives when a release needs action. Like the security patches in this release.

Add to stack