Security26.7.2
Keycloak 26.7.2 release
Keycloak 26.7.2 includes multiple critical security fixes addressing CVEs in OpenTelemetry, jackson-databind, fine-grained admin permissions, account linking, and credential reset flows, plus bug fixes and enhancements including a Quarkus upgrade.
Upgrading
Before upgrading refer to the migration guide for a complete list of changes.
All resolved issues
Security fixes
- #49570 CVE-2026-45292 OpenTelemetry Java SDK has Unbounded Memory Allocation in W3C Baggage Propagation
dependencies - #50616 [CVE-2026-14613] Keycloak 26.6.3 Fine-Grained Admin Permissions Bypass via Role Groups Endpoint
admin/fine-grained-permissions - #50955 [CVE-2026-59888 and CVE-2026-59889] Upgrade jackson-databind to 2.21.5 to fix
- #50966 [CVE-2026-15945] Group hierarchy search discloses hidden parent groups under FGAP v2
admin/fine-grained-permissions - #51145 [CVE-2026-17048] Keycloak Admin REST API Leaks Vault-Resolved Rotated Client Secrets
oidc - #51832 CVE-2026-15571 Predictable account-linking hash enables account takeover via malicious oidc client
- #51833 CVE-2026-18963 Unauthenticated account takeover via reset-credentials flow bypass
Weaknesses
- #50844 show-config prints the vault keystore password in cleartext
dist/quarkus
Enhancements
- #51344 Upgrade to Quarkus 3.33.3.1
Bugs
- #50751 Password denylist: false fpp warning on startup with large pre-computed .bloom file
authentication - #50849 Correct SCIM name.formated
scim - #50855 Rotated client secret remains valid when the feature is disabled
oidc - #51054 Invalid redirect URI on logout from pages with sub-tab hash fragments
admin/ui - #51061 Parameterized UserPropertyMapper exposes target user attributes without permission check
core - #51087 Passkey icons use wrong color variant when realm disables dark mode
authentication/webauthn - #51088 Verify email not working in incognito browser tab after Keycloak restart
authentication - #51131 Warning "Proactive closing of the session was missed - refinements are needed to TransactionSessionHandler related logic" appears
core - #51154 Upgrade to 26.7.0 fails with preview features as the stateless cluster provider captures a null NodeInfo before postInit
infinispan - #51164 WebAuthn tests are being skipped in Github workflows
workflows - #51182 Large HTTP/2 request headers are rejected with a bare 500 and no log; same request works over HTTP/1.1
dist/quarkus - #51323 Custom realm-level role named admin cannot be updated in non-master realms after Keycloak 26.7.0
admin/rbac - #51331 Adding org member fails with 500 with stateless:v1 feature enabled
organizations - #51407 The dist for Java API docs is empty
docs - #51449 Incorrect query parameter name for "max"
- #51476 Invalid link for https://www.ietf.org/rfc/rfc4559.txt
docs
securitybugfixoidcauthenticationadmin
Source: original entry ↗