This release includes 8 security fixes for security teams reviewing exposed deployments.
Published 1mo
Secrets & Credentials
✓ No known CVEs patched
This release patches 8 known CVEs
Topics
keycloak
oidc
saml
Affected surfaces
auth
rbac
Summary
AI summaryCVE-2026-9099: group-admin escalation to realm-admin
Full changelog
Upgrading
Before upgrading refer to the migration guide for a complete list of changes.
All resolved issues
Security fixes
- #50344 CVE-2026-9099 Keycloak: group-admin escalation to realm-admin
- #50345 CVE-2026-9083 Keycloak: keycloak: information disclosure through arbitrary filesystem path probing
- #50347 CVE-2026-9086 Keycloak: keycloak: cross-site scripting (xss) via case-insensitive uri validation bypass
- #50349 CVE-2026-9705 Keycloak: keycloak: attacker can re-enable and take over disabled clients via registration access token
- #50350 CVE-2026-9795 Keycloak: keycloak: privilege escalation via improper scope mapping enforcement
- #50351 CVE-2026-9799 Keycloak: keycloak: unauthorized access to resources via uma permission ticket bypass
- #50352 CVE-2026-9800 Keycloak: keycloak policy enforcer: authorization bypass via incorrect uri comparison
- #50357 CVE-2026-11800 Keycloak: Authentication bypass via JWT algorithm confusion
Enhancements
- #50100 Upgrade to Quarkus 3.33.2.1
Bugs
Security Fixes
- CVE-2026-9099 — group-admin escalation to realm-admin
- CVE-2026-9083 — information disclosure via arbitrary filesystem path probing
- CVE-2026-9086 — cross-site scripting (XSS) via case‑insensitive URI validation bypass
- CVE-2026-9705 — attacker can re‑enable and take over disabled clients via registration access token
- CVE-2026-9795 — privilege escalation via improper scope mapping enforcement
- CVE-2026-9799 — unauthorized access to resources via UMA permission ticket bypass
- CVE-2026-9800 — authorization bypass via incorrect URI comparison in policy enforcer
- CVE-2026-11800 — authentication bypass via JWT algorithm confusion
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About keycloak
Open Source Identity and Access Management For Modern Applications and Services
Related context
Beta — feedback welcome: [email protected]