Version 26.6.4 is a security-focused Keycloak release with fixes for disclosed vulnerabilities. It also upgrades Quarkus to 3., an informational dependency change for operators.
Action needed (8)
securityhighCVE-2026-9099, group-admin escalation to realm-admin
Version 26.6.4 fixes the group-admin escalation to realm-admin identified as CVE-2026-9099 in Keycloak.
securityhighCVE-2026-9086, cross-site scripting via URI validation bypass
Version 26.6.4 fixes the cross-site scripting issue caused by a case-insensitive URI validation bypass identified as CVE-2026-9086 in Keycloak.
securityhighCVE-2026-9795, improper scope mapping enforcement
Version 26.6.4 fixes the privilege escalation caused by improper scope mapping enforcement identified as CVE-2026-9795 in Keycloak.
securityhighCVE-2026-9800, policy enforcer URI comparison
Version 26.6.4 fixes the authorization bypass caused by incorrect URI comparison in the Keycloak policy enforcer, identified as CVE-2026-9800.
securityhighCVE-2026-11800, JWT algorithm confusion authentication bypass
Version 26.6.4 fixes the JWT algorithm confusion authentication bypass identified as CVE-2026-11800 in Keycloak.
securitymediumCVE-2026-9083, arbitrary filesystem path probing
Version 26.6.4 fixes the information disclosure through arbitrary filesystem path probing identified as CVE-2026-9083 in Keycloak.
securitymediumCVE-2026-9705, disabled client takeover
Version 26.6.4 fixes the issue identified as CVE-2026-9705, which allowed disabled clients to be re-enabled and taken over through a registration access token in Keycloak.
securitymediumCVE-2026-9799, UMA permission ticket bypass
Version 26.6.4 fixes the unauthorized resource access caused by a UMA permission ticket bypass identified as CVE-2026-9799 in Keycloak.