Skip to content

keycloak

v26.6.3 Security

This release includes 17 security fixes for security teams reviewing exposed deployments.

Published 1mo Secrets & Credentials
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 17 known CVEs

Topics

keycloak oidc saml

Affected surfaces

auth rbac rce_ssrf deps breaking_upgrade

ReleasePort's take

Moderate signal
editorial:auto 1mo

Keycloak 26.6.3 patches CVE‑2026‑4800, eliminating a code‑injection flaw in lodash template processing.

Why it matters: CVE‑2026‑4800 (severity 90) enables arbitrary code execution via `_.template` imports; upgrade to Keycloak 26.6.3 immediately if your deployment uses lodash templating.

Summary

AI summary

CVE-2026-4800 lodash code injection vulnerability fixed

Changes in this release

Security Critical

CVE-2026-9801 causes DoS in LDAP federation via malformed PasswordPolicyControl

CVE-2026-9801 causes DoS in LDAP federation via malformed PasswordPolicyControl

Source: llm_adapter@2026-06-04

Confidence: high

Security Critical

CVE-2026-4800 patches lodash code‑injection vulnerability via `_.template` imports

CVE-2026-4800 patches lodash code‑injection vulnerability via `_.template` imports

Source: llm_adapter@2026-06-04

Confidence: high

Security Critical

CVE-2026-4874 fixes Server‑Side Request Forgery via OIDC token endpoint manipulation

CVE-2026-4874 fixes Server‑Side Request Forgery via OIDC token endpoint manipulation

Source: llm_adapter@2026-06-04

Confidence: high

Security Critical

CVE-2026-9792 bypasses ROPC grant client policy enforcement in OIDC token endpoint

CVE-2026-9792 bypasses ROPC grant client policy enforcement in OIDC token endpoint

Source: llm_adapter@2026-06-04

Confidence: low

Security High

CVE-2026-37977 corrects CORS Access‑Control-Allow‑Origin reflection from unverified JWT azp claim on UMA token endpoint

CVE-2026-37977 corrects CORS Access‑Control-Allow‑Origin reflection from unverified JWT azp claim on UMA token endpoint

Source: llm_adapter@2026-06-04

Confidence: high

Security High

CVE-2026-7500 resolves Improper Access Control when the Account API feature is disabled

CVE-2026-7500 resolves Improper Access Control when the Account API feature is disabled

Source: llm_adapter@2026-06-04

Confidence: high

Security High

CVE-2026-42581 patches Netty HTTP/1.0 TE+CL coexistence bypassing smuggling sanitization

CVE-2026-42581 patches Netty HTTP/1.0 TE+CL coexistence bypassing smuggling sanitization

Source: llm_adapter@2026-06-04

Confidence: high

Security High

CVE-2026-8922 fixes OIDC token introspection ignoring realm‑level notBefore when client‑level is set

CVE-2026-8922 fixes OIDC token introspection ignoring realm‑level notBefore when client‑level is set

Source: llm_adapter@2026-06-04

Confidence: high

Security High

CVE-2026-8830 adds missing server‑side WebAuthn validations during credential registration

CVE-2026-8830 adds missing server‑side WebAuthn validations during credential registration

Source: llm_adapter@2026-06-04

Confidence: high

Security High

CVE-2026-9088 fixes Group Members Endpoint bypassing User Profile Permissions

CVE-2026-9088 fixes Group Members Endpoint bypassing User Profile Permissions

Source: granite4.1:30b@2026-06-04-audit

Confidence: high

Security High

CVE-2026-9087 fixes Cross‑Session Email Verification Proof not bound to upstream identity in First‑Broker‑Login

CVE-2026-9087 fixes Cross‑Session Email Verification Proof not bound to upstream identity in First‑Broker‑Login

Source: granite4.1:30b@2026-06-04-audit

Confidence: high

Security High

CVE-2026-9802 prevents refresh token reuse after server restart when revokeRefreshToken=true

CVE-2026-9802 prevents refresh token reuse after server restart when revokeRefreshToken=true

Source: granite4.1:30b@2026-06-04-audit

Confidence: high

Security High

CVE-2026-9794 stops SAML ECP faultstring from disclosing client existence and configuration state

CVE-2026-9794 stops SAML ECP faultstring from disclosing client existence and configuration state

Source: granite4.1:30b@2026-06-04-audit

Confidence: high

Security High

CVE-2026-9791 prevents Organization data exposure in tokens and Account API when Organizations feature is disabled

CVE-2026-9791 prevents Organization data exposure in tokens and Account API when Organizations feature is disabled

Source: granite4.1:30b@2026-06-04-audit

Confidence: high

Security High

CVE-2026-0707 fixes DoS via malformed Authorization header in ClientRegistrationAuth

CVE-2026-0707 fixes DoS via malformed Authorization header in ClientRegistrationAuth

Source: granite4.1:30b@2026-06-04-audit

Confidence: high

Security High

CVE-2026-9704 fixes privilege escalation via silent subject_token removal in token exchange

CVE-2026-9704 fixes privilege escalation via silent subject_token removal in token exchange

Source: granite4.1:30b@2026-06-04-audit

Confidence: high

Security High

CVE-2026-9792 fixes ROPC grant bypass in client policy enforcement

CVE-2026-9792 fixes ROPC grant bypass in client policy enforcement

Source: granite4.1:30b@2026-06-04-audit

Confidence: high

Feature Medium

Upgrade to Quarkus 3.33.2 improves platform performance and stability

Upgrade to Quarkus 3.33.2 improves platform performance and stability

Source: llm_adapter@2026-06-04

Confidence: low

Feature Low

Adds startup check for missing database indexes

Adds startup check for missing database indexes

Source: granite4.1:30b@2026-06-04-audit

Confidence: high

Feature Low

Introduces SPI option to disable FD_SOCK2 failure detection

Introduces SPI option to disable FD_SOCK2 failure detection

Source: granite4.1:30b@2026-06-04-audit

Confidence: high

Feature Low

Updates simple-git dependency to version 3.36.0

Updates simple-git dependency to version 3.36.0

Source: granite4.1:30b@2026-06-04-audit

Confidence: high

Feature Low

Updates uuid dependency to version ≥13.0.1

Updates uuid dependency to version ≥13.0.1

Source: granite4.1:30b@2026-06-04-audit

Confidence: high

Feature Low

Upgrades Quarkus to version 3.33.2

Upgrades Quarkus to version 3.33.2

Source: granite4.1:30b@2026-06-04-audit

Confidence: low

Bugfix High

Enforces host boundary for wildcard redirect URI matching in OIDC client configuration

Enforces host boundary for wildcard redirect URI matching in OIDC client configuration

Source: granite4.1:30b@2026-06-04-audit

Confidence: high

Bugfix High

Ensures async realm migrations are persisted before server exit

Ensures async realm migrations are persisted before server exit

Source: granite4.1:30b@2026-06-04-audit

Confidence: high

Bugfix Medium

Fixes handling of CORS requests in Admin UI, preventing ineffective CSRF protection

Fixes handling of CORS requests in Admin UI, preventing ineffective CSRF protection

Source: granite4.1:30b@2026-06-04-audit

Confidence: high

Bugfix Medium

Corrects UMA IS_ADMIN filter breaking ticket finding

Corrects UMA IS_ADMIN filter breaking ticket finding

Source: granite4.1:30b@2026-06-04-audit

Confidence: high

Bugfix Medium

Corrects ClientAdapter usage of isFrontChannelLogout flag

Corrects ClientAdapter usage of isFrontChannelLogout flag

Source: granite4.1:30b@2026-06-04-audit

Confidence: high

Bugfix Medium

Handles ContextNotActiveException during error processing

Handles ContextNotActiveException during error processing

Source: granite4.1:30b@2026-06-04-audit

Confidence: high

Bugfix Medium

Fixes missing indexes IDX_IDP_FOR_LOGIN and IDX_CLIENT_ATT_BY_NAME_VALUE for SQL Server

Fixes missing indexes IDX_IDP_FOR_LOGIN and IDX_CLIENT_ATT_BY_NAME_VALUE for SQL Server

Source: granite4.1:30b@2026-06-04-audit

Confidence: high

Bugfix Low

Reduces excessive user data returned by Account ResourceService user endpoint in UMA‑enabled realms

Reduces excessive user data returned by Account ResourceService user endpoint in UMA‑enabled realms

Source: granite4.1:30b@2026-06-04-audit

Confidence: high

Bugfix Low

Completes SCIM schema definition for objects

Completes SCIM schema definition for objects

Source: granite4.1:30b@2026-06-04-audit

Confidence: high

Full changelog

Upgrading

Before upgrading refer to the migration guide for a complete list of changes.

All resolved issues

Security fixes

  • #47707 CVE-2026-4800 lodash vulnerable to Code Injection via `_.template` imports key names account/ui
  • #47935 [CVE-2026-4874] Server-Side Request Forgery via OIDC token endpoint manipulation oidc
  • #48036 [CVE-2026-37977] CORS Access-Control-Allow-Origin reflected from unverified JWT azp claim on UMA token endpoint authorization-services
  • #48709 [CVE-2026-7500] Improper Access Control on Keycloak Server when the account Account API feature is disabled account/api
  • #48805 CVE-2026-42581 Netty HTTP/1.0 TE+CL Coexistence Bypasses Smuggling Sanitization
  • #49118 [CVE-2026-8922] OIDC token introspection ignores realm-level notBefore when client-level notBefore is set oidc
  • #49133 [CVE-2026-8830] Missing server-side WebAuthn validations during credential registration authentication/webauthn
  • #49174 [CVE-2026-9088] Group Members Endpoint Bypasses User Profile Permissions admin/fine-grained-permissions
  • #49175 [CVE-2026-9087] Cross-Session Email Verification Proof Not Bound to Upstream Identity in First-Broker-Login identity-brokering
  • #49426 [CVE-2026-9802] Server restart resets startupTime, allowing reuse of rotated refresh tokens when revokeRefreshToken=true oidc
  • #49428 [CVE-2026-9794] SAML ECP faultstring discloses client existence and configuration state saml
  • #49431 [CVE-2026-9791] Organization data exposed in tokens and account API when Organizations feature is disabled at realm level organizations
  • #49433 [CVE-2026-0707] ClientRegistrationAuth DoS via malformed Authorization header (CVE-2026-0707 incomplete fix) admin/api
  • #49434 [CVE-2026-9801] DoS in LDAP federation via malformed PasswordPolicyControl ldap
  • #49435 [CVE-2026-9704] Privilege escalation via silent subject_token removal in token exchange oidc
  • #49436 [CVE-2026-9792] ROPC grant bypass in client policy enforcement oidc

Weaknesses

  • #48978 UNSAFE_PATH_PATTERN regex to cover percent-encoded terminators and control characters oidc
  • #48986 Authorization Services: NullPointerException in UMA permission grant when stale permission ticket references removed scope authorization-services
  • #48987 Account API: Resource sharing endpoints ignore userManagedAccessAllowed realm setting authorization-services
  • #49086 Account resource sharing resolves recipient by username before email, granting access to wrong user authorization-services

Enhancements

  • #48311 Upgrade to Quarkus 3.33.2 dist/quarkus
  • #48695 Add startup check for missing database indexes
  • #49148 Add SPI option to disable FD_SOCK2 failure detection
  • #49526 Update to simple-git 3.36.0
  • #49530 Update to uuid >=13.0.1

Bugs

  • #45957 Handling of CORS requests in the Admin UI ineffective / open for CSRF admin/ui
  • #47036 Account ResourceService user endpoint returns excessive user data in UMA-enabled realms core
  • #48324 UMA IS_ADMIN filter breaks ticket finding authorization-services
  • #48430 Wildcard redirect URI matching does not enforce host boundary when * is placed directly after hostname oidc
  • #48432 ClientAdapter using wrong value for isFrontChannelLogout oidc
  • #48438 Keycloak 26.6.0/26.6.1 exits (code 1) ~100ms after async realm migration completes; migrations not persisted core
  • #48455 ContextNotActiveException during error handling core
  • #48464 Incomplete SCIM schema definition for objects scim
  • #48529 Broken downstream docs formatting on Kubernetes topic docs
  • #48584 Updating Keycloak to 26.6.x fails on SQL Server with case sensitive collation core
  • #48628 Client registerNode and unregisterNode endpoints fail authenticating the client core
  • #48681 ExternalLinksTest: oasis-open.org/standard/saml/ returns 403 in CI causing flaky documentation check ci
  • #48716 Missing index IDX_IDP_FOR_LOGIN and IDX_CLIENT_ATT_BY_NAME_VALUE for Microsoft SQL Server core
  • #48744 Input validation/ Unhandled NullPointerException on alg:none JWT in Bearer Authentication authentication
  • #48792 Virtual Thread checking is not working infinispan
  • #48806 NPE when accessing Account UI and the ACCOUNT feature is disabled account/api
  • #48877 Keycloak 26.6.1 does not persist UPDATE_PASSWORD for LDAP/AD federated users after temporary password reset ldap
  • #48904 Consistent 500 on DELETE of realms via non-browser clients calling REST API admin/api
  • #49058 Keycloak fails to run tests with embedded undertow dist/quarkus
  • #49140 Workflows documentation: offboarding example is incorrectly enclosing the list of revoked roles with double quotes workflows
  • #49149 Disable single thread sender in JGroups infinispan
  • #49151 FIPS jobs fail in CI because java-25-openjdk-devel package is missing testsuite
  • #49163 Enable JGroups message stats infinispan
  • #49194 Use Java 25 again for FIPS jobs testsuite
  • #49222 Incorrect link to Themes documentation docs
  • #49224 Broken links in UI Customization Guide docs
  • #49263 Use the PostgreSQL driver privacy option `logServerErrorDetail` dist/quarkus
  • #49265 Since Hibernate 7, the workaround to not log-and-throw Hibernate errors does not longer work dist/quarkus
  • #49274 JavaScript CI hangs when installing playwright testsuite
  • #49288 Link issue in the documentation for https://www.rfc-editor.org/rfc/rfc7662 docs
  • #49356 SAML async processing leaves a dangling threadlocal transaction dist/quarkus
  • #49611 Realm extensions require Bearer or Drop authorisation admin/api

Security Fixes

  • CVE-2026-4800 — lodash vulnerable to Code Injection via `_.template` imports
  • CVE-2026-4874
  • CVE-2026-37977
  • CVE-2026-7500
  • CVE-2026-42581
  • CVE-2026-8922
  • CVE-2026-8830
  • CVE-2026-9088
  • CVE-2026-9087
  • CVE-2026-9802
  • CVE-2026-9794
  • CVE-2026-9791
  • CVE-2026-0707
  • CVE-2026-0707
  • CVE-2026-9801
  • CVE-2026-9704
  • CVE-2026-9792

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track keycloak

Get notified when new releases ship.

Sign up free

About keycloak

Open Source Identity and Access Management For Modern Applications and Services

All releases →

Related context

Related CVEs

Featured in

Beta — feedback welcome: [email protected]