RATATOSKRATATOSK
Sign in

Releases

AI-analyzed release notes for CNCF graduated and incubating projects.

Jul 2026Clear ×Project: KeycloakClear ×
Keycloak26.7.0SecurityJul 9, 2026

A substantial operator-focused release that adds and promotes APIs, feature gates, administration capabilities, and deployment options. It also includes deprecations and removals, along with fixes for account takeover, log injection and audit forgery, key-attestation bypass, QR-code dimension denial of service, and four CVE-identified vulnerabilities.

Action needed (1)

  • securityPre-account takeover attack exposure

    The release corrects an issue that provided room for pre-account takeover attacks.

Check if affected (19)

  • securitymediumCVE-2026-9796, admin role rename authorization

    Applies if you use manage-clients.

    CVE-2026-9796 corrects a time-of-check to time-of-use bypass in admin role renaming that could enable realm-wide escalation from manage-clients.

  • securitymediumCVE-2026-9689, OIDC redirect URI parameter handling

    Applies if you use OIDC.

    CVE-2026-9689 corrects HTTP parameter pollution in the OIDC redirect URI, which allowed response parameter duplication.

  • securitymediumCVE-2026-9798, CIBA account lockout

    Applies if you run the CIBA authentication flow.

    CVE-2026-9798 corrects a bypass of brute-force account lockout in the CIBA authentication flow.

  • + 16 more on the release page

Plan ahead (4)

  • deprecatedThe V1 API, deprecated

    Applies if you use V1.

    V1 is deprecated in this release but remains enabled by default for backward compatibility.

  • deprecatedThe Require Discoverable Credential option, deprecated

    Applies if you configure the Require Discoverable Credential option.

    The Require Discoverable Credential option is deprecated in this release.

  • deprecatedThe Twitter IDP implementation, deprecated

    Applies if you use the Twitter IDP implementation.

    The Twitter IDP implementation is deprecated because it uses the old twitter4j library.

  • + 1 more on the release page
Source
Browse by month