A substantial operator-focused release that adds and promotes APIs, feature gates, administration capabilities, and deployment options. It also includes deprecations and removals, along with fixes for account takeover, log injection and audit forgery, key-attestation bypass, QR-code dimension denial of service, and four CVE-identified vulnerabilities.
Action needed (1)
securityPre-account takeover attack exposure
The release corrects an issue that provided room for pre-account takeover attacks.
Check if affected (19)
securitymediumCVE-2026-9796, admin role rename authorization
Applies if you use
manage-clients.CVE-2026-9796 corrects a time-of-check to time-of-use bypass in admin role renaming that could enable realm-wide escalation from
manage-clients.securitymediumCVE-2026-9689, OIDC redirect URI parameter handling
Applies if you use
OIDC.CVE-2026-9689 corrects HTTP parameter pollution in the
OIDCredirect URI, which allowed response parameter duplication.securitymediumCVE-2026-9798, CIBA account lockout
Applies if you run the
CIBAauthentication flow.CVE-2026-9798 corrects a bypass of brute-force account lockout in the
CIBAauthentication flow.- + 16 more on the release page
Plan ahead (4)
deprecatedThe
V1API, deprecatedApplies if you use
V1.V1is deprecated in this release but remains enabled by default for backward compatibility.deprecatedThe
Require Discoverable Credentialoption, deprecatedApplies if you configure the
Require Discoverable Credentialoption.The
Require Discoverable Credentialoption is deprecated in this release.deprecatedThe Twitter IDP implementation, deprecated
Applies if you use the Twitter IDP implementation.
The Twitter IDP implementation is deprecated because it uses the old
twitter4jlibrary.- + 1 more on the release page