RATATOSKRATATOSK
Sign in

Keycloak

26.7.2Security
Aug 19, 2026

ACTION 1CHECK 6OTHER 15

A security-focused maintenance release with fixes for authorization, disclosure, account-takeover, and cleartext credential issues. It also updates dependencies, including Quarkus, and resolves numerous bugs.

Action needed (1)

Check if affected (6)

  • securitycriticalCVE-2026-18963 reset-credentials flow bypass

    Applies if you use reset-credentials flow.

    CVE-2026-18963 fixes an unauthenticated account takeover through a reset-credentials flow bypass in Keycloak 26.7.2.

  • securityhighCVE-2026-15571 predictable account-linking hash

    Applies if you use an oidc client.

    CVE-2026-15571 fixes a predictable account-linking hash that enables account takeover through a malicious OIDC client in Keycloak 26.7.2.

  • securitymediumCVE-2026-14613 fine-grained admin permissions bypass

    Applies if you use admin/fine-grained-permissions.

    CVE-2026-14613 fixes a fine-grained admin permissions bypass through the role groups endpoint in Keycloak 26.7.2.

  • securitymediumCVE-2026-15945 hidden parent group disclosure

    Applies if you use admin/fine-grained-permissions.

    CVE-2026-15945 fixes group hierarchy searches disclosing hidden parent groups under FGAP v2 in Keycloak 26.7.2.

  • securitymediumCVE-2026-17048 rotated client secret disclosure

    Applies if you use Keycloak Admin REST API.

    CVE-2026-17048 fixes the Keycloak Admin REST API leaking Vault-resolved rotated client secrets in Keycloak 26.7.2.

  • securityCleartext vault keystore password from show-config

    Applies if you run show-config.

    Keycloak 26.7.2 fixes show-config printing the vault keystore password in cleartext.

All 15 other recorded changessecurity fixes 1 · fixes 13 · value changes 1

security fixes (1)

  • CVE-2026-45292 OpenTelemetry Java SDK has Unbounded Memory Allocation in W3C Baggage Propagation

fixes (13)

  • Password denylist: false fpp warning on startup with large pre-computed .bloom file
  • Correct SCIM name.formated
  • Rotated client secret remains valid when the feature is disabled
  • Invalid redirect URI on logout from pages with sub-tab hash fragments
  • Parameterized UserPropertyMapper exposes target user attributes without permission check
  • Passkey icons use wrong color variant when realm disables dark mode
  • Verify email not working in incognito browser tab after Keycloak restart
  • Warning "Proactive closing of the session was missed - refinements are needed to TransactionSessionHandler related logic" appears
  • Upgrade to 26.7.0 fails with preview features as the stateless cluster provider captures a null NodeInfo before postInit
  • Large HTTP/2 request headers are rejected with a bare 500 and no log; same request works over HTTP/1.1
  • Custom realm-level role named admin cannot be updated in non-master realms after Keycloak 26.7.0
  • Adding org member fails with 500 with stateless:v1 feature enabled
  • Incorrect query parameter name for "max"

value changes (1)

  • Upgrade to Quarkus 3.33.3.1
Add Keycloak to your stack

A weekly email arrives when a release needs action. Like the security patches in this release.

Add to stack