A maintenance release with disclosed security fixes, a cleartext vault-keystore password correction, a Quarkus dependency upgrade, and other bug corrections. The fixes cover account and permission flows, secret handling, and runtime dependencies.
Action needed (2)
securitymediumCVE-2026-59888 and CVE-2026-59889 fixes in
jackson-databindjackson-databindis upgraded to 2.21.5 to address CVE-2026-59888 and CVE-2026-59889. The dependency update ships in this Keycloak release.securitymediumCVE-2026-45292 OpenTelemetry Java SDK memory allocation correction
CVE-2026-45292 corrects unbounded memory allocation in W3C Baggage Propagation in the OpenTelemetry Java SDK.
Check if affected (6)
securitycriticalCVE-2026-18963 reset-credentials flow bypass correction
Applies if you use the
reset-credentials flow.CVE-2026-18963 corrects an unauthenticated account takeover caused by a bypass in the reset-credentials flow.
securityhighCVE-2026-15571 predictable account-linking hash correction
Applies if you use
oidc.CVE-2026-15571 corrects the predictable account-linking hash that enabled account takeover through a malicious
oidcclient.securitymediumCVE-2026-14613 fine-grained admin permissions bypass correction
Applies if you use the
admin/fine-grained-permissionsAPI.CVE-2026-14613 corrects a fine-grained admin permissions bypass through the
admin/fine-grained-permissionsRole Groups endpoint.- + 3 more on the release page