This release includes 17 security fixes for security teams reviewing exposed deployments.
Topics
Affected surfaces
ReleasePort's take
Moderate signalKeycloak 26.6.3 patches CVE‑2026‑4800, eliminating a code‑injection flaw in lodash template processing.
Why it matters: CVE‑2026‑4800 (severity 90) enables arbitrary code execution via `_.template` imports; upgrade to Keycloak 26.6.3 immediately if your deployment uses lodash templating.
Summary
AI summaryCVE-2026-4800 lodash code injection vulnerability fixed
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Critical |
CVE-2026-9801 causes DoS in LDAP federation via malformed PasswordPolicyControl CVE-2026-9801 causes DoS in LDAP federation via malformed PasswordPolicyControl Source: llm_adapter@2026-06-04 Confidence: high |
— |
| Security | Critical |
CVE-2026-4800 patches lodash code‑injection vulnerability via `_.template` imports CVE-2026-4800 patches lodash code‑injection vulnerability via `_.template` imports Source: llm_adapter@2026-06-04 Confidence: high |
— |
| Security | Critical |
CVE-2026-4874 fixes Server‑Side Request Forgery via OIDC token endpoint manipulation CVE-2026-4874 fixes Server‑Side Request Forgery via OIDC token endpoint manipulation Source: llm_adapter@2026-06-04 Confidence: high |
— |
| Security | Critical |
CVE-2026-9792 bypasses ROPC grant client policy enforcement in OIDC token endpoint CVE-2026-9792 bypasses ROPC grant client policy enforcement in OIDC token endpoint Source: llm_adapter@2026-06-04 Confidence: low |
— |
| Security | High |
CVE-2026-37977 corrects CORS Access‑Control-Allow‑Origin reflection from unverified JWT azp claim on UMA token endpoint CVE-2026-37977 corrects CORS Access‑Control-Allow‑Origin reflection from unverified JWT azp claim on UMA token endpoint Source: llm_adapter@2026-06-04 Confidence: high |
— |
| Security | High |
CVE-2026-7500 resolves Improper Access Control when the Account API feature is disabled CVE-2026-7500 resolves Improper Access Control when the Account API feature is disabled Source: llm_adapter@2026-06-04 Confidence: high |
— |
| Security | High |
CVE-2026-42581 patches Netty HTTP/1.0 TE+CL coexistence bypassing smuggling sanitization CVE-2026-42581 patches Netty HTTP/1.0 TE+CL coexistence bypassing smuggling sanitization Source: llm_adapter@2026-06-04 Confidence: high |
— |
| Security | High |
CVE-2026-8922 fixes OIDC token introspection ignoring realm‑level notBefore when client‑level is set CVE-2026-8922 fixes OIDC token introspection ignoring realm‑level notBefore when client‑level is set Source: llm_adapter@2026-06-04 Confidence: high |
— |
| Security | High |
CVE-2026-8830 adds missing server‑side WebAuthn validations during credential registration CVE-2026-8830 adds missing server‑side WebAuthn validations during credential registration Source: llm_adapter@2026-06-04 Confidence: high |
— |
| Security | High |
CVE-2026-9088 fixes Group Members Endpoint bypassing User Profile Permissions CVE-2026-9088 fixes Group Members Endpoint bypassing User Profile Permissions Source: granite4.1:30b@2026-06-04-audit Confidence: high |
— |
| Security | High |
CVE-2026-9087 fixes Cross‑Session Email Verification Proof not bound to upstream identity in First‑Broker‑Login CVE-2026-9087 fixes Cross‑Session Email Verification Proof not bound to upstream identity in First‑Broker‑Login Source: granite4.1:30b@2026-06-04-audit Confidence: high |
— |
| Security | High |
CVE-2026-9802 prevents refresh token reuse after server restart when revokeRefreshToken=true CVE-2026-9802 prevents refresh token reuse after server restart when revokeRefreshToken=true Source: granite4.1:30b@2026-06-04-audit Confidence: high |
— |
| Security | High |
CVE-2026-9794 stops SAML ECP faultstring from disclosing client existence and configuration state CVE-2026-9794 stops SAML ECP faultstring from disclosing client existence and configuration state Source: granite4.1:30b@2026-06-04-audit Confidence: high |
— |
| Security | High |
CVE-2026-9791 prevents Organization data exposure in tokens and Account API when Organizations feature is disabled CVE-2026-9791 prevents Organization data exposure in tokens and Account API when Organizations feature is disabled Source: granite4.1:30b@2026-06-04-audit Confidence: high |
— |
| Security | High |
CVE-2026-0707 fixes DoS via malformed Authorization header in ClientRegistrationAuth CVE-2026-0707 fixes DoS via malformed Authorization header in ClientRegistrationAuth Source: granite4.1:30b@2026-06-04-audit Confidence: high |
— |
| Security | High |
CVE-2026-9704 fixes privilege escalation via silent subject_token removal in token exchange CVE-2026-9704 fixes privilege escalation via silent subject_token removal in token exchange Source: granite4.1:30b@2026-06-04-audit Confidence: high |
— |
| Security | High |
CVE-2026-9792 fixes ROPC grant bypass in client policy enforcement CVE-2026-9792 fixes ROPC grant bypass in client policy enforcement Source: granite4.1:30b@2026-06-04-audit Confidence: high |
— |
| Feature | Medium |
Upgrade to Quarkus 3.33.2 improves platform performance and stability Upgrade to Quarkus 3.33.2 improves platform performance and stability Source: llm_adapter@2026-06-04 Confidence: low |
— |
| Feature | Low |
Adds startup check for missing database indexes Adds startup check for missing database indexes Source: granite4.1:30b@2026-06-04-audit Confidence: high |
— |
| Feature | Low |
Introduces SPI option to disable FD_SOCK2 failure detection Introduces SPI option to disable FD_SOCK2 failure detection Source: granite4.1:30b@2026-06-04-audit Confidence: high |
— |
| Feature | Low |
Updates simple-git dependency to version 3.36.0 Updates simple-git dependency to version 3.36.0 Source: granite4.1:30b@2026-06-04-audit Confidence: high |
— |
| Feature | Low |
Updates uuid dependency to version ≥13.0.1 Updates uuid dependency to version ≥13.0.1 Source: granite4.1:30b@2026-06-04-audit Confidence: high |
— |
| Feature | Low |
Upgrades Quarkus to version 3.33.2 Upgrades Quarkus to version 3.33.2 Source: granite4.1:30b@2026-06-04-audit Confidence: low |
— |
| Bugfix | High |
Enforces host boundary for wildcard redirect URI matching in OIDC client configuration Enforces host boundary for wildcard redirect URI matching in OIDC client configuration Source: granite4.1:30b@2026-06-04-audit Confidence: high |
— |
| Bugfix | High |
Ensures async realm migrations are persisted before server exit Ensures async realm migrations are persisted before server exit Source: granite4.1:30b@2026-06-04-audit Confidence: high |
— |
| Bugfix | Medium |
Fixes handling of CORS requests in Admin UI, preventing ineffective CSRF protection Fixes handling of CORS requests in Admin UI, preventing ineffective CSRF protection Source: granite4.1:30b@2026-06-04-audit Confidence: high |
— |
| Bugfix | Medium |
Corrects UMA IS_ADMIN filter breaking ticket finding Corrects UMA IS_ADMIN filter breaking ticket finding Source: granite4.1:30b@2026-06-04-audit Confidence: high |
— |
| Bugfix | Medium |
Corrects ClientAdapter usage of isFrontChannelLogout flag Corrects ClientAdapter usage of isFrontChannelLogout flag Source: granite4.1:30b@2026-06-04-audit Confidence: high |
— |
| Bugfix | Medium |
Handles ContextNotActiveException during error processing Handles ContextNotActiveException during error processing Source: granite4.1:30b@2026-06-04-audit Confidence: high |
— |
| Bugfix | Medium |
Fixes missing indexes IDX_IDP_FOR_LOGIN and IDX_CLIENT_ATT_BY_NAME_VALUE for SQL Server Fixes missing indexes IDX_IDP_FOR_LOGIN and IDX_CLIENT_ATT_BY_NAME_VALUE for SQL Server Source: granite4.1:30b@2026-06-04-audit Confidence: high |
— |
| Bugfix | Low |
Reduces excessive user data returned by Account ResourceService user endpoint in UMA‑enabled realms Reduces excessive user data returned by Account ResourceService user endpoint in UMA‑enabled realms Source: granite4.1:30b@2026-06-04-audit Confidence: high |
— |
| Bugfix | Low |
Completes SCIM schema definition for objects Completes SCIM schema definition for objects Source: granite4.1:30b@2026-06-04-audit Confidence: high |
— |
Full changelog
Upgrading
Before upgrading refer to the migration guide for a complete list of changes.
All resolved issues
Security fixes
- #47707 CVE-2026-4800 lodash vulnerable to Code Injection via `_.template` imports key names
account/ui - #47935 [CVE-2026-4874] Server-Side Request Forgery via OIDC token endpoint manipulation
oidc - #48036 [CVE-2026-37977] CORS Access-Control-Allow-Origin reflected from unverified JWT azp claim on UMA token endpoint
authorization-services - #48709 [CVE-2026-7500] Improper Access Control on Keycloak Server when the account Account API feature is disabled
account/api - #48805 CVE-2026-42581 Netty HTTP/1.0 TE+CL Coexistence Bypasses Smuggling Sanitization
- #49118 [CVE-2026-8922] OIDC token introspection ignores realm-level notBefore when client-level notBefore is set
oidc - #49133 [CVE-2026-8830] Missing server-side WebAuthn validations during credential registration
authentication/webauthn - #49174 [CVE-2026-9088] Group Members Endpoint Bypasses User Profile Permissions
admin/fine-grained-permissions - #49175 [CVE-2026-9087] Cross-Session Email Verification Proof Not Bound to Upstream Identity in First-Broker-Login
identity-brokering - #49426 [CVE-2026-9802] Server restart resets startupTime, allowing reuse of rotated refresh tokens when revokeRefreshToken=true
oidc - #49428 [CVE-2026-9794] SAML ECP faultstring discloses client existence and configuration state
saml - #49431 [CVE-2026-9791] Organization data exposed in tokens and account API when Organizations feature is disabled at realm level
organizations - #49433 [CVE-2026-0707] ClientRegistrationAuth DoS via malformed Authorization header (CVE-2026-0707 incomplete fix)
admin/api - #49434 [CVE-2026-9801] DoS in LDAP federation via malformed PasswordPolicyControl
ldap - #49435 [CVE-2026-9704] Privilege escalation via silent subject_token removal in token exchange
oidc - #49436 [CVE-2026-9792] ROPC grant bypass in client policy enforcement
oidc
Weaknesses
- #48978 UNSAFE_PATH_PATTERN regex to cover percent-encoded terminators and control characters
oidc - #48986 Authorization Services: NullPointerException in UMA permission grant when stale permission ticket references removed scope
authorization-services - #48987 Account API: Resource sharing endpoints ignore userManagedAccessAllowed realm setting
authorization-services - #49086 Account resource sharing resolves recipient by username before email, granting access to wrong user
authorization-services
Enhancements
- #48311 Upgrade to Quarkus 3.33.2
dist/quarkus - #48695 Add startup check for missing database indexes
- #49148 Add SPI option to disable FD_SOCK2 failure detection
- #49526 Update to simple-git 3.36.0
- #49530 Update to uuid >=13.0.1
Bugs
- #45957 Handling of CORS requests in the Admin UI ineffective / open for CSRF
admin/ui - #47036 Account ResourceService user endpoint returns excessive user data in UMA-enabled realms
core - #48324 UMA IS_ADMIN filter breaks ticket finding
authorization-services - #48430 Wildcard redirect URI matching does not enforce host boundary when * is placed directly after hostname
oidc - #48432 ClientAdapter using wrong value for isFrontChannelLogout
oidc - #48438 Keycloak 26.6.0/26.6.1 exits (code 1) ~100ms after async realm migration completes; migrations not persisted
core - #48455 ContextNotActiveException during error handling
core - #48464 Incomplete SCIM schema definition for objects
scim - #48529 Broken downstream docs formatting on Kubernetes topic
docs - #48584 Updating Keycloak to 26.6.x fails on SQL Server with case sensitive collation
core - #48628 Client registerNode and unregisterNode endpoints fail authenticating the client
core - #48681 ExternalLinksTest: oasis-open.org/standard/saml/ returns 403 in CI causing flaky documentation check
ci - #48716 Missing index IDX_IDP_FOR_LOGIN and IDX_CLIENT_ATT_BY_NAME_VALUE for Microsoft SQL Server
core - #48744 Input validation/ Unhandled NullPointerException on alg:none JWT in Bearer Authentication
authentication - #48792 Virtual Thread checking is not working
infinispan - #48806 NPE when accessing Account UI and the ACCOUNT feature is disabled
account/api - #48877 Keycloak 26.6.1 does not persist UPDATE_PASSWORD for LDAP/AD federated users after temporary password reset
ldap - #48904 Consistent 500 on DELETE of realms via non-browser clients calling REST API
admin/api - #49058 Keycloak fails to run tests with embedded undertow
dist/quarkus - #49140 Workflows documentation: offboarding example is incorrectly enclosing the list of revoked roles with double quotes
workflows - #49149 Disable single thread sender in JGroups
infinispan - #49151 FIPS jobs fail in CI because java-25-openjdk-devel package is missing
testsuite - #49163 Enable JGroups message stats
infinispan - #49194 Use Java 25 again for FIPS jobs
testsuite - #49222 Incorrect link to Themes documentation
docs - #49224 Broken links in UI Customization Guide
docs - #49263 Use the PostgreSQL driver privacy option `logServerErrorDetail`
dist/quarkus - #49265 Since Hibernate 7, the workaround to not log-and-throw Hibernate errors does not longer work
dist/quarkus - #49274 JavaScript CI hangs when installing playwright
testsuite - #49288 Link issue in the documentation for https://www.rfc-editor.org/rfc/rfc7662
docs - #49356 SAML async processing leaves a dangling threadlocal transaction
dist/quarkus - #49611 Realm extensions require Bearer or Drop authorisation
admin/api
Security Fixes
- CVE-2026-4800 — lodash vulnerable to Code Injection via `_.template` imports
- CVE-2026-4874
- CVE-2026-37977
- CVE-2026-7500
- CVE-2026-42581
- CVE-2026-8922
- CVE-2026-8830
- CVE-2026-9088
- CVE-2026-9087
- CVE-2026-9802
- CVE-2026-9794
- CVE-2026-9791
- CVE-2026-0707
- CVE-2026-0707
- CVE-2026-9801
- CVE-2026-9704
- CVE-2026-9792
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About keycloak
Open Source Identity and Access Management For Modern Applications and Services
Related context
Related tools
Related CVEs
- CVE-2026-0707 NVD KEV EPSS
- CVE-2026-37977 NVD KEV EPSS
- CVE-2026-42581 NVD KEV EPSS
- CVE-2026-4800 NVD KEV EPSS
- CVE-2026-4874 NVD KEV EPSS
- CVE-2026-7500 NVD KEV EPSS
- CVE-2026-8830 NVD KEV EPSS
- CVE-2026-8922 NVD KEV EPSS
- CVE-2026-9087 NVD KEV EPSS
- CVE-2026-9088 NVD KEV EPSS
- CVE-2026-9704 NVD KEV EPSS
- CVE-2026-9791 NVD KEV EPSS
- CVE-2026-9792 NVD KEV EPSS
- CVE-2026-9794 NVD KEV EPSS
- CVE-2026-9801 NVD KEV EPSS
- CVE-2026-9802 NVD KEV EPSS
Featured in
Beta — feedback welcome: [email protected]