Keycloak
26.7.2SecurityA security-focused maintenance release with fixes for authorization, disclosure, account-takeover, and cleartext credential issues. It also updates dependencies, including Quarkus, and resolves numerous bugs.
Action needed (1)
securitymedium
jackson-databind2.21.5 update for CVE-2026-59888 and CVE-2026-59889Keycloak 26.7.2 upgrades
jackson-databindto2.to fix CVE-2026-59888 and CVE-2026-59889.21. 5
Check if affected (6)
securitycriticalCVE-2026-18963 reset-credentials flow bypass
Applies if you use
reset-credentials flow.CVE-2026-18963 fixes an unauthenticated account takeover through a reset-credentials flow bypass in Keycloak 26.7.2.
securityhighCVE-2026-15571 predictable account-linking hash
Applies if you use an
oidc client.CVE-2026-15571 fixes a predictable account-linking hash that enables account takeover through a malicious OIDC client in Keycloak 26.7.2.
securitymediumCVE-2026-14613 fine-grained admin permissions bypass
Applies if you use
admin/fine-grained-permissions.CVE-2026-14613 fixes a fine-grained admin permissions bypass through the role groups endpoint in Keycloak 26.7.2.
securitymediumCVE-2026-15945 hidden parent group disclosure
Applies if you use
admin/fine-grained-permissions.CVE-2026-15945 fixes group hierarchy searches disclosing hidden parent groups under FGAP v2 in Keycloak 26.7.2.
securitymediumCVE-2026-17048 rotated client secret disclosure
Applies if you use
Keycloak Admin REST API.CVE-2026-17048 fixes the
Keycloak Admin REST APIleaking Vault-resolved rotated client secrets in Keycloak 26.7.2.securityCleartext vault keystore password from
show-configApplies if you run
show-config.Keycloak 26.7.2 fixes
show-configprinting the vault keystore password in cleartext.
All 15 other recorded changessecurity fixes 1 · fixes 13 · value changes 1
security fixes (1)
- CVE-2026-45292 OpenTelemetry Java SDK has Unbounded Memory Allocation in W3C Baggage Propagation
fixes (13)
- Password denylist: false fpp warning on startup with large pre-computed .bloom file
- Correct SCIM name.formated
- Rotated client secret remains valid when the feature is disabled
- Invalid redirect URI on logout from pages with sub-tab hash fragments
- Parameterized UserPropertyMapper exposes target user attributes without permission check
- Passkey icons use wrong color variant when realm disables dark mode
- Verify email not working in incognito browser tab after Keycloak restart
- Warning "Proactive closing of the session was missed - refinements are needed to TransactionSessionHandler related logic" appears
- Upgrade to 26.7.0 fails with preview features as the stateless cluster provider captures a null NodeInfo before postInit
- Large HTTP/2 request headers are rejected with a bare 500 and no log; same request works over HTTP/1.1
- Custom realm-level role named admin cannot be updated in non-master realms after Keycloak 26.7.0
- Adding org member fails with 500 with stateless:v1 feature enabled
- Incorrect query parameter name for "max"
value changes (1)
- Upgrade to Quarkus 3.33.3.1
A weekly email arrives when a release needs action. Like the security patches in this release.