Skip to content
Release Radar

Keycloak

Security

Identity and access management for modern applications and services

26.7.416 days after 26.7.3
View on GitHub

Release history

26.7.4

CompareGitHub

<div>

<h2>Upgrading</h2> <p>Before upgrading refer to <a href="https://www.keycloak.org/docs/latest/upgrading/#migration-changes">the migration guide</a> for a complete list of changes.</p>

<h2>All resolved issues</h2>

<h3>Security fixes</h3> <ul> <li><a href="https://github.com/keycloak/keycloak/issues/52834">#52834</a> [CVE-2026-90997] Default MySQL/MariaDB row counts make stateless replay gates accept reused artifacts </li> <li><a href="https://github.com/keycloak/keycloak/issues/52835">#52835</a> [CVE-2026-79651] Keycloak Unauthenticated Denial of Service via Unbounded Locale Caching </li> <li><a href="https://github.com/keycloak/keycloak/issues/52836">#52836</a> [CVE-2026-74909] Incomplete fix: percent-encoded semicolon bypasses matrix parameter stripping in PathMatcher </li> <li><a href="https://github.com/keycloak/keycloak/issues/52837">#52837</a> [CVE-2026-19607] Username Takeover Leading to Account Lockout </li> <li><a href="https://github.com/keycloak/keycloak/issues/52838">#52838</a> [CVE-2026-17526] Privilege escalation: the "impersonation" role can impersonate a realm administrator </li> <li><a href="https://github.com/keycloak/keycloak/issues/52839">#52839</a> [CVE-2026-18212] SAML Redirect DEFLATE helpers leak native zlib state </li> </ul>

<h3>Enhancements</h3> <ul> <li><a href="https://github.com/keycloak/keycloak/issues/52354">#52354</a> Upgrade to Quarkus 3.33.3.2 <code>dist/quarkus</code></li> </ul>

<h3>Bugs</h3> <ul> <li><a href="https://github.com/keycloak/keycloak/issues/49635">#49635</a> Performance issue with 26.6.2 <code>dist/quarkus</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/51102">#51102</a> Flaky test: org.keycloak.testsuite.oauth.AccessTokenTest#accessTokenRequest <code>ci</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/52015">#52015</a> New links errors for https://quarkus.io/guides <code>docs</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/52172">#52172</a> Cached RealmAdapter.isUserManagedAccessAllowed() returns isEnabled() <code>infinispan</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/52173">#52173</a> realm_client is computed into a client's attributes and then persisted on save <code>admin/api</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/52233">#52233</a> Oracle 19 full client OCI driver crashes on startup since 26.6.0 — SQLFeatureNotSupportedException on setNetworkTimeout <code>dist/quarkus</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/52241">#52241</a> Clicking on a sub group in the admin console throws an exception <code>admin/ui</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/52283">#52283</a> Flaky test SessionRestServiceTest.testGetDevicesSessions <code>testsuite</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/52430">#52430</a> Flaky test: userprofile.spec.ts fails with timeout on "no-users-found-empty-action" in serial suite <code>testsuite</code></li> </ul>

</div>

<div>

<h2>Upgrading</h2> <p>Before upgrading refer to <a href="https://www.keycloak.org/docs/latest/upgrading/#migration-changes">the migration guide</a> for a complete list of changes.</p>

<h2>All resolved issues</h2>

<h3>Security fixes</h3> <ul> <li><a href="https://github.com/keycloak/keycloak/issues/50785">#50785</a> CVE-2026-35563: LDAP client implementation in version 2.1.7 does not verify if the server certificate matches the intended LDAP hostname <code>ldap</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/50997">#50997</a> [CVE-2026-16093] Required signed-JWT assertion policy can be bypassed with unsigned assertion headers <code>oidc</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/50998">#50998</a> [CVE-2026-16072] Organization managers can create managed members through stored registration links without manage-users <code>organizations</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/51001">#51001</a> [CVE-2026-16108] Realm default-group reads disclose hidden groups under FGAP v2 <code>admin/fine-grained-permissions</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/51002">#51002</a> [CVE-2026-16105] Missing per-role authorization on RoleContainerResource composite endpoints <code>admin/rbac</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/51003">#51003</a> [CVE-2026-16089] Authorization codes can be retargeted to another client session <code>oidc</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/51005">#51005</a> [CVE-2026-16104] Authenticator config surfaces expose raw reCAPTCHA secrets <code>admin/fine-grained-permissions</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/51112">#51112</a> [CVE-2026-16106] Incorrect authorization in admin role-composite deletion allows delegated admin to remove privileged child roles <code>admin/fine-grained-permissions</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/51142">#51142</a> [CVE-2026-17059] Information disclosure: GET /roles/{role}/users returns user PII without the per-user view filter <code>admin/fine-grained-permissions</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/51279">#51279</a> [CVE-2026-18218] Client not-before revocation is ignored when realm not-before is older but nonzero <code>oidc</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/51282">#51282</a> [CVE-2026-18215] Microsoft external access-token exchange bypasses configured tenant <code>token-exchange</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/51283">#51283</a> [CVE-2026-18201] Generic identity-provider creation can bind brokers to organizations without manage-organizations <code>organizations</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/51286">#51286</a> [CVE-2026-18209] Incomplete fix for redirect_uri OIDC response-parameter injection: forbidden-parameter check (commit 18832bca) inspects only the query string, not the URL fragment <code>oidc</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/51287">#51287</a> [CVE-2026-18214] Google external access-token exchange bypasses hosted-domain restriction <code>token-exchange</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/51378">#51378</a> [CVE-2026-18571] FGAP V2: Group assignment bypass during user creation (POST /users) allows adding unpermitted groups <code>admin/fine-grained-permissions</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/51379">#51379</a> [CVE-2026-18572] UMA claim token can override the authorization time-policy clock <code>authorization-services</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/51380">#51380</a> [CVE-2026-18573] Client access-type condition evaluates updates against the old client type <code>oidc</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/51382">#51382</a> [CVE-2026-18570] Full-scope-disabled client policy validation can be bypassed by omitting fullScopeAllowed <code>oidc</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/51745">#51745</a> [CVE-2026-19729] Incomplete fix for CVE-2026-9083 — relative path traversal still enables filesystem probing in 26.6.4 <code>core</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/52028">#52028</a> [CVE-2026-79652] Keycloak jwt-bearer authorization grant does not enforce consentRequired <code>oidc</code></li> </ul>

<h3>Weaknesses</h3> <ul> <li><a href="https://github.com/keycloak/keycloak/issues/50581">#50581</a> Admin API: User/group role-mapping endpoints disclose hidden client role metadata under FGAP v2 <code>admin/fine-grained-permissions</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/50583">#50583</a> Admin API: Composite role endpoints do not filter child roles by FGAP v2 view permission <code>admin/fine-grained-permissions</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/50990">#50990</a> Admin UI extension effective-role endpoints disclose hidden composite roles <code>admin/fine-grained-permissions</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/51143">#51143</a> Aggregate policy partial evaluation diverges from runtime semantics under FGAP v2 <code>admin/fine-grained-permissions</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/51144">#51144</a> Partial evaluation misses ancestor group policies with extendChildren <code>admin/fine-grained-permissions</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/51202">#51202</a> Client-protocol condition can be bypassed on admin client creation by omitting protocol <code>oidc</code></li> </ul>

<h3>Bugs</h3> <ul> <li><a href="https://github.com/keycloak/keycloak/issues/50825">#50825</a> Creating an organization without a domain leads to an error <code>organizations</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/50963">#50963</a> V1 token-exchange strips the DPoP sender-constraint from a bound access token <code>token-exchange</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/51510">#51510</a> SQLGrammarException: The incoming request has too many parameters <code>core</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/51523">#51523</a> Sustained high CPU on all nodes after upgrade <code>admin/api</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/51554">#51554</a> Admin API per-request cost grows super-linearly with realm count since 26.7.1 <code>admin/api</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/51589">#51589</a> NPE in RoleUtils.expandCompositeRoles when a cached client scope references a deleted role <code>core</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/51602">#51602</a> Invalid redirect on https://access.redhat.com/products/red-hat-single-sign-on/ <code>docs</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/51707">#51707</a> Lightweight access token role resolution resolves all roles across all realms on every admin API request <code>core</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/51712">#51712</a> Logout URL does not allow OIDC response parameters in its redirect_url <code>oidc</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/51780">#51780</a> SSSD CI job fails: FreeIPA container crashes on ubuntu-24.04 runner image 20260810.271 <code>ci</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/51785">#51785</a> Multiple CVEs inherited from Apache DS used for testing </li> <li><a href="https://github.com/keycloak/keycloak/issues/51790">#51790</a> Java Distribution IT/UT (windows-latest, temurin, 21) times out regularly <code>ci</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/51792">#51792</a> AsyncCommitIntegrator Aurora detection logs "ERROR: function aurora_version() does not exist" in the PostgreSQL server log on every startup </li> <li><a href="https://github.com/keycloak/keycloak/issues/51807">#51807</a> Client scope boundary bypassed when resolving admin roles via KeycloakIdentity <code>admin/fine-grained-permissions</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/51902">#51902</a> Index modifiers are not logged if an index is not created due to a threshold <code>core</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/51920">#51920</a> Error: 1020-HY000: Record has changed since last read in table OFFLINE_CLIENT_SESSION </li> <li><a href="https://github.com/keycloak/keycloak/issues/51983">#51983</a> [26.7.2] Regression in UI in JS keycloak-admin-client </li> <li><a href="https://github.com/keycloak/keycloak/issues/52017">#52017</a> SAML ECP faultstring discloses client existence, incomplete fix of CVE-2026-9794 <code>saml</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/52038">#52038</a> Client session note removals are not persisted with persistent user sessions <code>core</code></li> </ul>

</div>

<div>

<h2>Upgrading</h2> <p>Before upgrading refer to <a href="https://www.keycloak.org/docs/latest/upgrading/#migration-changes">the migration guide</a> for a complete list of changes.</p>

<h2>All resolved issues</h2>

<h3>Security fixes</h3> <ul> <li><a href="https://github.com/keycloak/keycloak/issues/49570">#49570</a> CVE-2026-45292 OpenTelemetry Java SDK has Unbounded Memory Allocation in W3C Baggage Propagation <code>dependencies</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/50616">#50616</a> [CVE-2026-14613] Keycloak 26.6.3 Fine-Grained Admin Permissions Bypass via Role Groups Endpoint <code>admin/fine-grained-permissions</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/50955">#50955</a> [CVE-2026-59888 and CVE-2026-59889] Upgrade jackson-databind to 2.21.5 to fix </li> <li><a href="https://github.com/keycloak/keycloak/issues/50966">#50966</a> [CVE-2026-15945] Group hierarchy search discloses hidden parent groups under FGAP v2 <code>admin/fine-grained-permissions</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/51145">#51145</a> [CVE-2026-17048] Keycloak Admin REST API Leaks Vault-Resolved Rotated Client Secrets <code>oidc</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/51832">#51832</a> CVE-2026-15571 Predictable account-linking hash enables account takeover via malicious oidc client </li> <li><a href="https://github.com/keycloak/keycloak/issues/51833">#51833</a> CVE-2026-18963 Unauthenticated account takeover via reset-credentials flow bypass </li> </ul>

<h3>Weaknesses</h3> <ul> <li><a href="https://github.com/keycloak/keycloak/issues/50844">#50844</a> show-config prints the vault keystore password in cleartext <code>dist/quarkus</code></li> </ul>

<h3>Enhancements</h3> <ul> <li><a href="https://github.com/keycloak/keycloak/issues/51344">#51344</a> Upgrade to Quarkus 3.33.3.1 </li> </ul>

<h3>Bugs</h3> <ul> <li><a href="https://github.com/keycloak/keycloak/issues/50751">#50751</a> Password denylist: false fpp warning on startup with large pre-computed .bloom file <code>authentication</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/50849">#50849</a> Correct SCIM name.formated <code>scim</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/50855">#50855</a> Rotated client secret remains valid when the feature is disabled <code>oidc</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/51054">#51054</a> Invalid redirect URI on logout from pages with sub-tab hash fragments <code>admin/ui</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/51061">#51061</a> Parameterized UserPropertyMapper exposes target user attributes without permission check <code>core</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/51087">#51087</a> Passkey icons use wrong color variant when realm disables dark mode <code>authentication/webauthn</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/51088">#51088</a> Verify email not working in incognito browser tab after Keycloak restart <code>authentication</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/51131">#51131</a> Warning "Proactive closing of the session was missed - refinements are needed to TransactionSessionHandler related logic" appears <code>core</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/51154">#51154</a> Upgrade to 26.7.0 fails with preview features as the stateless cluster provider captures a null NodeInfo before postInit <code>infinispan</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/51164">#51164</a> WebAuthn tests are being skipped in Github workflows <code>workflows</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/51182">#51182</a> Large HTTP/2 request headers are rejected with a bare 500 and no log; same request works over HTTP/1.1 <code>dist/quarkus</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/51323">#51323</a> Custom realm-level role named admin cannot be updated in non-master realms after Keycloak 26.7.0 <code>admin/rbac</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/51331">#51331</a> Adding org member fails with 500 with stateless:v1 feature enabled <code>organizations</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/51407">#51407</a> The dist for Java API docs is empty <code>docs</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/51449">#51449</a> Incorrect query parameter name for "max" </li> <li><a href="https://github.com/keycloak/keycloak/issues/51476">#51476</a> Invalid link for https://www.ietf.org/rfc/rfc4559.txt <code>docs</code></li> </ul>

</div>

<div>

<h2>Upgrading</h2> <p>Before upgrading refer to <a href="https://www.keycloak.org/docs/latest/upgrading/#migration-changes">the migration guide</a> for a complete list of changes.</p>

<h2>All resolved issues</h2>

<h3>Security fixes</h3> <ul> <li><a href="https://github.com/keycloak/keycloak/issues/49429">#49429</a> [CVE-2026-9793] JWE request object bypasses requestObjectSignatureAlg enforcement <code>oidc</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/50445">#50445</a> [CVE-2026-4629] Privilege escalation via hardcoded role mapper injection in manage-clients <code>admin/api</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/50569">#50569</a> [CVE-2026-14209] Keycloak Admin UI Extension brute-force-user User Disclosure via search=id: under FGAP v2 <code>admin/fine-grained-permissions</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/50615">#50615</a> [CVE-2026-14614] Keycloak 26.6.3 Fine-Grained Admin Permissions Bypass in Client Scope Assignment <code>admin/fine-grained-permissions</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/50617">#50617</a> [CVE-2026-14615] FGAP v2 parent group children endpoint bypasses per-child view permission filter <code>admin/fine-grained-permissions</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/51467">#51467</a> CVE-2026-15573 Authorization bypass via unnormalized uri matching in pathmatcher </li> <li><a href="https://github.com/keycloak/keycloak/issues/51468">#51468</a> CVE-2026-15572 DCR protocol mapper type-swap policy bypass allows privilege escalation </li> <li><a href="https://github.com/keycloak/keycloak/issues/51469">#51469</a> CVE-2026-16100 Unbounded metric cardinality in user event metrics via request-controlled error text </li> <li><a href="https://github.com/keycloak/keycloak/issues/51470">#51470</a> CVE-2026-16442 SAML idp-initiated broker login bypasses link-only restriction </li> <li><a href="https://github.com/keycloak/keycloak/issues/51471">#51471</a> CVE-2026-16443 SAML broker metadata import disables response signature validation </li> <li><a href="https://github.com/keycloak/keycloak/issues/51472">#51472</a> CVE-2026-16071 LDAP entry-dn user search bypasses configured users dn boundary </li> <li><a href="https://github.com/keycloak/keycloak/issues/51473">#51473</a> CVE-2026-16102 Default DCR policy allows role forgery via user property mappers </li> </ul>

<h3>Bugs</h3> <ul> <li><a href="https://github.com/keycloak/keycloak/issues/50719">#50719</a> WebAuthn authenticator attachment policy is bypassed when the client omits the attachment field <code>authentication/webauthn</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/50750">#50750</a> Clustering test broken in 26.7 release branch <code>ci</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/50836">#50836</a> Kustomize cluster-wide faulty Role&RoleBinding <code>operator</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/50850">#50850</a> New Password is commited when multiple Password Reset is detected <code>authentication</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/50882">#50882</a> 500 when client requests organization scope with it already set to Default <code>authentication</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/50928">#50928</a> IllegalFormatConversionException in LiquibaseDBLockProviderFactory and wrong time conversion <code>core</code></li> </ul>

</div>

<div> <h2>Highlights</h2> <div class="paragraph"> <p>This release features new capabilities for users and administrators of Keycloak. The highlights of this release are:</p> </div> <div class="ulist"> <ul> <li> <p>Automate user provisioning with the SCIM API (preview)</p> </li> <li> <p>Simplified multi-cluster high availability without external caches (preview)</p> </li> <li> <p>Enhanced reverse proxy guides with blueprints for HAProxy and Traefik</p> </li> <li> <p>Step-up authentication for SAML clients</p> </li> </ul> </div> <div class="paragraph"> <p>Read on to learn more about each new feature. If you are upgrading from a previous release, <a href="https://www.keycloak.org/docs/latest/upgrading/index.html">also review the changes listed in the upgrading guide</a>.</p> </div> <div class="sect2"> <h3 id="_security_and_standards">Security and Standards</h3> <div class="sect3"> <h4 id="_stronger_security_for_the_identity_brokering_api">Stronger security for the Identity Brokering API</h4> <div class="paragraph"> <p>The Identity Brokering API allows applications to retrieve tokens obtained from external identity providers during federated login. Version 2 of this API replaces the legacy V1 with a more secure and standards-compliant design:</p> </div> <div class="ulist"> <ul> <li> <p><strong>Client-level authorization</strong> — access to external tokens is controlled per client using dedicated settings (<strong>Allow retrieve external tokens</strong> and an identity provider allow list) instead of assigning broker roles to individual users.</p> </li> <li> <p><strong>Confidential clients only</strong> — public clients are rejected, ensuring that only authenticated clients can retrieve external tokens.</p> </li> <li> <p><strong>OAuth 2.0 compliant</strong> — the endpoint uses <code>POST</code> and returns standard JSON responses with <code>access_token</code>, <code>error</code>, and <code>error_description</code> fields.</p> </li> <li> <p><strong>Session-based token storage</strong> — a new <strong>Store token in session</strong> option keeps tokens in the user session for faster access, with automatic cleanup on session expiry. Database storage remains available for persistence across sessions.</p> </li> </ul> </div> <div class="paragraph"> <p>V2 is now supported but disabled by default. V1 is deprecated but still enabled by default for backward compatibility. In a future release, V1 will be removed and V2 will become the default.</p> </div> <div class="paragraph"> <p>For more information, see the <a href="https://www.keycloak.org/docs/26.7.0/server_development/#_identity-brokering-apis">Identity Brokering APIs</a> chapter in the Server Developer Guide.</p> </div> </div> <div class="sect3"> <h4 id="_progress_on_verifiable_credentials_oid4vci_experimental">Progress on Verifiable Credentials (OID4VCI) (experimental)</h4> <div class="paragraph"> <p><a href="https://openid.net/specs/openid-4-verifiable-credential-issuance-1_0.html">Verifiable Credentials (OID4VCI)</a> allow organizations to issue tamper-proof, cryptographically signed credentials — such as employee badges, academic diplomas, or professional certifications — that users can store in a digital wallet and present to third parties without involving the issuer.</p> </div> <div class="paragraph"> <p>OID4VCI remains an experimental feature in Keycloak, but this release brings substantial improvements from both the core team and the community:</p> </div> <div class="ulist"> <ul> <li> <p>Polishing of existing functionality and improving configuration. Everything is now configurable in the admin UI in addition to the admin REST API.</p> </li> <li> <p>Lots of bugs fixed. Improved specification compliance.</p> </li> <li> <p>Conformance with the <a href="https://openid.net/specs/openid4vc-high-assurance-interoperability-profile-1_0.html">OpenID4VC High Assurance Interoperability Profile (HAIP)</a>. This work involves the introduction of the dedicated Keycloak experimental feature <code>client-auth-abca</code> for <a href="https://datatracker.ietf.org/doc/html/draft-ietf-oauth-attestation-based-client-auth-07">Attestation based client authentication (ABCA)</a>.</p> </li> <li> <p>Management of verifiable credentials for individual users. This involves the ability for an administrator to create a verifiable credential for a user to indicate that this user can retrieve a verifiable credential, as well as the ability for users to start issuance of a verifiable credential from the Keycloak account console.</p> </li> <li> <p><a href="https://openid.net/specs/openid-4-verifiable-credential-issuance-1_0.html#name-pre-authorized-code-flow">Pre-authorized code grant</a> support is still experimental and was moved to the dedicated experimental feature <code>oid4vc-vci-preauth-code</code></p> </li> <li> <p>Support for credential refresh interval. Administrators can now configure a separate refresh interval (<code>vc.refresh_interval_in_seconds</code>) in the client scope settings that controls how often wallets must refresh the credential, independent of the credential lifetime. When not explicitly set, defaults to 7 days or the credential lifetime, whichever is smaller. This enables regular credential rotation for enhanced security while maintaining user convenience through automatic refresh using the refresh token. For more information, see the <a href="https://www.keycloak.org/docs/26.7.0/server_admin/#_oid4vci_client_scope">Create Client Scopes with Mappers</a> section in the OID4VCI configuration guide.</p> </li> <li> <p>Documentation updated and improved</p> </li> </ul> </div> <div class="paragraph"> <p>Many community members were involved in the development. Many thanks to <a href="https://github.com/Awambeng">Awambeng</a>, <a href="https://github.com/Captain-P-Goldfish">Pascal Knüppel</a>, <a href="https://github.com/dominikschlosser">Dominik Schlosser</a>, <a href="https://github.com/forkimenjeckayang">forkimenjeckayang</a>, <a href="https://github.com/IngridPuppet">Ingrid Kamga</a>, <a href="https://github.com/keshavprashantdeshpande">Keshav Deshpande</a>, <a href="https://github.com/namanONcode">Naman Jain</a>, <a href="https://github.com/officialasishkumar">Asish Kumar</a>, <a href="https://github.com/Ogenbertrand">Ogen Bertrand</a>, <a href="https://github.com/Oluwatobi-Mustapha">Oluwatobi Mustapha</a>, <a href="https://github.com/pulsastrix">Hugo Hakim Damer</a>, <a href="https://github.com/rameshkumarkoyya">rameshkumarkoyya</a>, <a href="https://github.com/tdiesler">Thomas Diesler</a> and <a href="https://github.com/Vitalisn4">Palpable</a> for the contributions!</p> </div> </div> <div class="sect3"> <h4 id="_cross_domain_token_exchange_with_identity_assertion_jwt_grant_experimental">Cross-domain token exchange with Identity Assertion JWT Grant (experimental)</h4> <div class="paragraph"> <p>When two organizations each run their own authorization server, users often need to re-authenticate when crossing between them — even though their identity was already verified. The <a href="https://datatracker.ietf.org/doc/html/draft-ietf-oauth-identity-assertion-authz-grant">Identity Assertion JWT Authorization Grant (ID-JAG)</a> solves this by allowing one authorization server to present a signed identity assertion to another, which then issues an access token without requiring the user to log in again.</p> </div> <div class="paragraph"> <p>Keycloak provides partial experimental support for the Identity Assertion JWT Authorization Grant. It currently implements only the receiving authorization server role, accepting ID-JAG assertions at the token endpoint and issuing access tokens in return. Other parts of the ID-JAG specification are not yet implemented, so the complete flow is not currently supported.</p> </div> <div class="paragraph"> <p>To try it out, start Keycloak with the feature <code>identity-assertion-jwt</code> enabled.</p> </div> <div class="paragraph"> <p>Many thanks to <a href="https://github.com/bucchi">Yutaka Obuchi</a> for the contribution of this feature!</p> </div> </div> <div class="sect3"> <h4 id="_automate_user_provisioning_with_the_scim_api_preview">Automate user provisioning with the SCIM API (preview)</h4> <div class="paragraph"> <p><a href="https://datatracker.ietf.org/doc/html/rfc7644">SCIM</a> (System for Cross-domain Identity Management) is a standard protocol for reading and writing identity resources such as users and groups across multiple systems. It enables organizations to automate user provisioning and deprovisioning using widely available tooling — for example, integrating with identity governance platforms, HR systems, or other identity providers.</p> </div> <div class="paragraph"> <p>Keycloak has SCIM APIs for managing users and groups within a realm. The implementation covers full CRUD and PATCH operations, filtering and pagination, schema extensions including the Enterprise User extension, and schema discovery endpoints.</p> </div> <div class="paragraph"> <p>In this release, the SCIM API is being promoted to a preview feature. In the default profile it is disabled by default; to try it out, enable the <code>scim-api</code> feature.</p> </div> <div class="paragraph"> <p>For more details, see the <a href="https://www.keycloak.org/docs/26.7.0/server_admin/#_managing_scim">Managing users and groups through SCIM</a> documentation.</p> </div> </div> <div class="sect3"> <h4 id="_real_time_security_signals_to_downstream_applications_experimental">Real-time security signals to downstream applications (experimental)</h4> <div class="paragraph"> <p>When a user logs out, changes credentials, or gets disabled in Keycloak, downstream applications typically don&#8217;t learn about it until the next token refresh — leaving a window where stale sessions remain active. The <a href="https://openid.net/specs/openid-s

…(truncated)

<div>

<h2>Upgrading</h2> <p>Before upgrading refer to <a href="https://www.keycloak.org/docs/latest/upgrading/#migration-changes">the migration guide</a> for a complete list of changes.</p>

<h2>All resolved issues</h2>

<h3>Security fixes</h3> <ul> <li><a href="https://github.com/keycloak/keycloak/issues/50344">#50344</a> CVE-2026-9099 Keycloak: group-admin escalation to realm-admin </li> <li><a href="https://github.com/keycloak/keycloak/issues/50345">#50345</a> CVE-2026-9083 Keycloak: keycloak: information disclosure through arbitrary filesystem path probing </li> <li><a href="https://github.com/keycloak/keycloak/issues/50347">#50347</a> CVE-2026-9086 Keycloak: keycloak: cross-site scripting (xss) via case-insensitive uri validation bypass </li> <li><a href="https://github.com/keycloak/keycloak/issues/50349">#50349</a> CVE-2026-9705 Keycloak: keycloak: attacker can re-enable and take over disabled clients via registration access token </li> <li><a href="https://github.com/keycloak/keycloak/issues/50350">#50350</a> CVE-2026-9795 Keycloak: keycloak: privilege escalation via improper scope mapping enforcement </li> <li><a href="https://github.com/keycloak/keycloak/issues/50351">#50351</a> CVE-2026-9799 Keycloak: keycloak: unauthorized access to resources via uma permission ticket bypass </li> <li><a href="https://github.com/keycloak/keycloak/issues/50352">#50352</a> CVE-2026-9800 Keycloak: keycloak policy enforcer: authorization bypass via incorrect uri comparison </li> <li><a href="https://github.com/keycloak/keycloak/issues/50357">#50357</a> CVE-2026-11800 Keycloak: Authentication bypass via JWT algorithm confusion </li> </ul>

<h3>Enhancements</h3> <ul> <li><a href="https://github.com/keycloak/keycloak/issues/50100">#50100</a> Upgrade to Quarkus 3.33.2.1 </li> </ul>

<h3>Bugs</h3> <ul> <li><a href="https://github.com/keycloak/keycloak/issues/47999">#47999</a> [Keycloak JavaScript CI] - Build Keycloak <code>ci</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/49639">#49639</a> Keycloak Admin Client tests fails in CI <code>ci</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/49700">#49700</a> Incorrect migration guide reference <code>docs</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/49707">#49707</a> Cannot build project due to ISPN protoschema and 26.2 branch <code>infinispan</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/49733">#49733</a> keycloak-api-docs-dist is not deployable <code>dist/quarkus</code></li> </ul>

</div>

<div>

<h2>Upgrading</h2> <p>Before upgrading refer to <a href="https://www.keycloak.org/docs/latest/upgrading/#migration-changes">the migration guide</a> for a complete list of changes.</p>

<h2>All resolved issues</h2>

<h3>Security fixes</h3> <ul> <li><a href="https://github.com/keycloak/keycloak/issues/47707">#47707</a> CVE-2026-4800 lodash vulnerable to Code Injection via _.template imports key names <code>account/ui</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/47935">#47935</a> [CVE-2026-4874] Server-Side Request Forgery via OIDC token endpoint manipulation <code>oidc</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/48036">#48036</a> [CVE-2026-37977] CORS Access-Control-Allow-Origin reflected from unverified JWT azp claim on UMA token endpoint <code>authorization-services</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/48709">#48709</a> [CVE-2026-7500] Improper Access Control on Keycloak Server when the account Account API feature is disabled <code>account/api</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/48805">#48805</a> CVE-2026-42581 Netty HTTP/1.0 TE+CL Coexistence Bypasses Smuggling Sanitization </li> <li><a href="https://github.com/keycloak/keycloak/issues/49118">#49118</a> [CVE-2026-8922] OIDC token introspection ignores realm-level notBefore when client-level notBefore is set <code>oidc</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/49133">#49133</a> [CVE-2026-8830] Missing server-side WebAuthn validations during credential registration <code>authentication/webauthn</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/49174">#49174</a> [CVE-2026-9088] Group Members Endpoint Bypasses User Profile Permissions <code>admin/fine-grained-permissions</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/49175">#49175</a> [CVE-2026-9087] Cross-Session Email Verification Proof Not Bound to Upstream Identity in First-Broker-Login <code>identity-brokering</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/49426">#49426</a> [CVE-2026-9802] Server restart resets startupTime, allowing reuse of rotated refresh tokens when revokeRefreshToken=true <code>oidc</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/49428">#49428</a> [CVE-2026-9794] SAML ECP faultstring discloses client existence and configuration state <code>saml</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/49431">#49431</a> [CVE-2026-9791] Organization data exposed in tokens and account API when Organizations feature is disabled at realm level <code>organizations</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/49433">#49433</a> [CVE-2026-0707] ClientRegistrationAuth DoS via malformed Authorization header (CVE-2026-0707 incomplete fix) <code>admin/api</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/49434">#49434</a> [CVE-2026-9801] DoS in LDAP federation via malformed PasswordPolicyControl <code>ldap</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/49435">#49435</a> [CVE-2026-9704] Privilege escalation via silent subject_token removal in token exchange <code>oidc</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/49436">#49436</a> [CVE-2026-9792] ROPC grant bypass in client policy enforcement <code>oidc</code></li> </ul>

<h3>Weaknesses</h3> <ul> <li><a href="https://github.com/keycloak/keycloak/issues/48978">#48978</a> UNSAFE_PATH_PATTERN regex to cover percent-encoded terminators and control characters <code>oidc</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/48986">#48986</a> Authorization Services: NullPointerException in UMA permission grant when stale permission ticket references removed scope <code>authorization-services</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/48987">#48987</a> Account API: Resource sharing endpoints ignore userManagedAccessAllowed realm setting <code>authorization-services</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/49086">#49086</a> Account resource sharing resolves recipient by username before email, granting access to wrong user <code>authorization-services</code></li> </ul>

<h3>Enhancements</h3> <ul> <li><a href="https://github.com/keycloak/keycloak/issues/48311">#48311</a> Upgrade to Quarkus 3.33.2 <code>dist/quarkus</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/48695">#48695</a> Add startup check for missing database indexes </li> <li><a href="https://github.com/keycloak/keycloak/issues/49148">#49148</a> Add SPI option to disable FD_SOCK2 failure detection </li> <li><a href="https://github.com/keycloak/keycloak/issues/49526">#49526</a> Update to simple-git 3.36.0 </li> <li><a href="https://github.com/keycloak/keycloak/issues/49530">#49530</a> Update to uuid >=13.0.1 </li> </ul>

<h3>Bugs</h3> <ul> <li><a href="https://github.com/keycloak/keycloak/issues/45957">#45957</a> Handling of CORS requests in the Admin UI ineffective / open for CSRF <code>admin/ui</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/47036">#47036</a> Account ResourceService user endpoint returns excessive user data in UMA-enabled realms <code>core</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/48324">#48324</a> UMA IS_ADMIN filter breaks ticket finding <code>authorization-services</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/48430">#48430</a> Wildcard redirect URI matching does not enforce host boundary when * is placed directly after hostname <code>oidc</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/48432">#48432</a> ClientAdapter using wrong value for isFrontChannelLogout <code>oidc</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/48438">#48438</a> Keycloak 26.6.0/26.6.1 exits (code 1) ~100ms after async realm migration completes; migrations not persisted <code>core</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/48455">#48455</a> ContextNotActiveException during error handling <code>core</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/48464">#48464</a> Incomplete SCIM schema definition for objects <code>scim</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/48529">#48529</a> Broken downstream docs formatting on Kubernetes topic <code>docs</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/48584">#48584</a> Updating Keycloak to 26.6.x fails on SQL Server with case sensitive collation <code>core</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/48628">#48628</a> Client registerNode and unregisterNode endpoints fail authenticating the client <code>core</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/48681">#48681</a> ExternalLinksTest: oasis-open.org/standard/saml/ returns 403 in CI causing flaky documentation check <code>ci</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/48716">#48716</a> Missing index IDX_IDP_FOR_LOGIN and IDX_CLIENT_ATT_BY_NAME_VALUE for Microsoft SQL Server <code>core</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/48744">#48744</a> Input validation/ Unhandled NullPointerException on alg:none JWT in Bearer Authentication <code>authentication</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/48792">#48792</a> Virtual Thread checking is not working <code>infinispan</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/48806">#48806</a> NPE when accessing Account UI and the ACCOUNT feature is disabled <code>account/api</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/48877">#48877</a> Keycloak 26.6.1 does not persist UPDATE_PASSWORD for LDAP/AD federated users after temporary password reset <code>ldap</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/48904">#48904</a> Consistent 500 on DELETE of realms via non-browser clients calling REST API <code>admin/api</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/49058">#49058</a> Keycloak fails to run tests with embedded undertow <code>dist/quarkus</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/49140">#49140</a> Workflows documentation: offboarding example is incorrectly enclosing the list of revoked roles with double quotes <code>workflows</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/49149">#49149</a> Disable single thread sender in JGroups <code>infinispan</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/49151">#49151</a> FIPS jobs fail in CI because java-25-openjdk-devel package is missing <code>testsuite</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/49163">#49163</a> Enable JGroups message stats <code>infinispan</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/49194">#49194</a> Use Java 25 again for FIPS jobs <code>testsuite</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/49222">#49222</a> Incorrect link to Themes documentation <code>docs</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/49224">#49224</a> Broken links in UI Customization Guide <code>docs</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/49263">#49263</a> Use the PostgreSQL driver privacy option logServerErrorDetail <code>dist/quarkus</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/49265">#49265</a> Since Hibernate 7, the workaround to not log-and-throw Hibernate errors does not longer work <code>dist/quarkus</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/49274">#49274</a> JavaScript CI hangs when installing playwright <code>testsuite</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/49288">#49288</a> Link issue in the documentation for https://www.rfc-editor

…(truncated)

<div>

<h2>Upgrading</h2> <p>Before upgrading refer to <a href="https://www.keycloak.org/docs/latest/upgrading/#migration-changes">the migration guide</a> for a complete list of changes.</p>

<h2>All resolved issues</h2>

<h3>Security fixes</h3> <ul> <li><a href="https://github.com/keycloak/keycloak/issues/47485">#47485</a> CVE-2026-33871 HTTP/2 CONTINUATION Frame Flood Denial of Service </li> <li><a href="https://github.com/keycloak/keycloak/issues/47486">#47486</a> CVE-2026-33870 RFC violation: HTTP Request Smuggling primitive via Chunked Extension Quoted-String Parsing </li> <li><a href="https://github.com/keycloak/keycloak/issues/47932">#47932</a> [CVE-2026-4628] Improper Access Control on Keycloak Server through UMA resource management endpoints via PUT parameters <code>authorization-services</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/48049">#48049</a> [CVE-2026-37980] Stored XSS in select-organization.ftl - FreeMarker HTML-escape insufficient in inline JS handler <code>organizations</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/48275">#48275</a> CVE-2026-5588 Bouncy Castle Crypto Package For Java: Use of a Broken or Risky Cryptographic Algorithm vulnerability in bcpkix modules <code>core</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/48388">#48388</a> [CVE-2026-6856] Acceptable AAGUID policy bypass via packed self-attestation in WebAuthn registration <code>authentication/webauthn</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/48570">#48570</a> [CVE‐2026‐0636, CVE‐2026‐3505, CVE‐2026‐5598] Multiple bouncycastle CVEs <code>core</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/49108">#49108</a> [CVE-2026-7307] Denial of service when sending a crafted request to the /saml endpoint </li> <li><a href="https://github.com/keycloak/keycloak/issues/49109">#49109</a> [CVE-2026-7504] Security Vulnerability Report: Redirect URI Validation Bypass in Keycloak </li> <li><a href="https://github.com/keycloak/keycloak/issues/49110">#49110</a> [CVE-2026-7571] Access token disclosure and implicit flow bypass via forged client data </li> <li><a href="https://github.com/keycloak/keycloak/issues/49111">#49111</a> [CVE-2026-7507] Session fixation in OIDC login flow leading to account takeover </li> <li><a href="https://github.com/keycloak/keycloak/issues/49112">#49112</a> [CVE-2026-37982] Execute-actions token replay allows unauthorized WebAuthn credential enrollment on victim account </li> <li><a href="https://github.com/keycloak/keycloak/issues/49113">#49113</a> [CVE-2026-37979] OIDC Introspection endpoint does not enforce audience restriction, leaking claims from lightweight access tokens </li> <li><a href="https://github.com/keycloak/keycloak/issues/49114">#49114</a> [CVE-2026-37978] Cross-role PII leakage via evaluate-scopes endpoints bypasses user view permission </li> <li><a href="https://github.com/keycloak/keycloak/issues/49115">#49115</a> [CVE-2026-4630] Keycloak Authorization Services Protection API IDOR (Cross-Resource Server Access) </li> <li><a href="https://github.com/keycloak/keycloak/issues/49116">#49116</a> [CVE-2026-37981] Broken Access Control in Account Resources User Lookup allows PII enumeration </li> </ul>

<h3>Enhancements</h3> <ul> <li><a href="https://github.com/keycloak/keycloak/issues/47728">#47728</a> Monitor backups for CNPG - describe how to monitor it in the CNPG for backups installation guide </li> <li><a href="https://github.com/keycloak/keycloak/issues/47734">#47734</a> Add dedicated "Monitoring Standbys" section to the general installation documentation </li> <li><a href="https://github.com/keycloak/keycloak/issues/48329">#48329</a> JDBC_PING in 26.6 should not fail with 26.7 schema changes </li> <li><a href="https://github.com/keycloak/keycloak/issues/48348">#48348</a> Escape expressions in JS blocks in FTL pages </li> <li><a href="https://github.com/keycloak/keycloak/issues/48687">#48687</a> Upgrade to Quarkus 3.33.1.1 </li> </ul>

<h3>Bugs</h3> <ul> <li><a href="https://github.com/keycloak/keycloak/issues/38526">#38526</a> Duplicate user attribute values cannot be removed <code>core</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/40602">#40602</a> Account UI reports "Something went wrong" when opening an unknown path <code>account/ui</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/47882">#47882</a> Broken link in deploy-cnpg <code>docs</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/47901">#47901</a> Realm import with --import-realm fails with ModelValidationException when Admin Permissions is enabled <code>admin/fine-grained-permissions</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/47915">#47915</a> FreeMarker templates allow instantiation of new objects and even running OS commands <code>login/ui</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/47987">#47987</a> FGAP v2 Specific Group permission has no scopes found in resource <code>admin/fine-grained-permissions</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/48030">#48030</a> Update to operator version 26.6.0 needs deletion of all objects <code>operator</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/48040">#48040</a> User session limit generates fatal error <code>authentication</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/48094">#48094</a> Wrong referenced resource type in Workflow handling for clients <code>core</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/48123">#48123</a> Clarify canonicalization in X.509 authentication <code>authentication</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/48143">#48143</a> Ordering of permission and policy calls leads to exposure of a client ID <code>admin/api</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/48185">#48185</a> Deleted workflow still attempting to run <code>workflows</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/48241">#48241</a> JavaScript Injection in frontchannel-logout.ftl via frontchannel-logout.title <code>authentication</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/48259">#48259</a> Kubernetes identity providers docs still mention it to be a preview feature <code>docs</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/48313">#48313</a> No escape approach for JS code inside the front channel logout FTL <code>login/ui</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/48536">#48536</a> Review migration guide for rolling updates changes <code>workflows</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/48629">#48629</a> WindowsServiceDistTest.testServiceLifecycle fails on slower runners due to insufficient startup timeout <code>ci</code></li> </ul>

</div>

<div>

<h2>Upgrading</h2> <p>Before upgrading refer to <a href="https://www.keycloak.org/docs/latest/upgrading/#migration-changes">the migration guide</a> for a complete list of changes.</p>

<h2>All resolved issues</h2>

<h3>Security fixes</h3> <ul> <li><a href="https://github.com/keycloak/keycloak/issues/47276">#47276</a> CVE-2026-4366 Blind Server-Side Request Forgery (SSRF) via HTTP Redirect Handling <code>core</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/47619">#47619</a> CVE-2026-4633 Keycloak user enumeration via identity-first login <code>core</code></li> </ul>

<h3>Enhancements</h3> <ul> <li><a href="https://github.com/keycloak/keycloak/issues/47839">#47839</a> Update CloudNativePG to 1.29 </li> <li><a href="https://github.com/keycloak/keycloak/issues/47909">#47909</a> Database data at rest encryption </li> </ul>

<h3>Bugs</h3> <ul> <li><a href="https://github.com/keycloak/keycloak/issues/47435">#47435</a> AuroraDB IT CI workflow not cleaning up databases <code>testsuite</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/47737">#47737</a> deploy-testsuite profile is incomplete, causing discrete testsuite execution to fail <code>testsuite</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/47776">#47776</a> False session type of access token in offline_access refresh token flow with scope parameter without offline_access scope <code>oidc</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/47827">#47827</a> az vm create fails with JSON parsing error <code>ci</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/47872">#47872</a> v26.6.0 Operator flood logs with warnings <code>operator</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/47889">#47889</a> Not possible to sync latest keycloak-admin-client to keycloak-client <code>admin/client-java</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/47904">#47904</a> @keycloak/keycloak-admin-client fails to install in version 26.6.0 <code>admin/client-js</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/47905">#47905</a> invalid package reference in keycloak-admin-ui <code>admin/ui</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/47908">#47908</a> MigrateTo26_6_0 modifies custom browser flows, breaking existing realm authentication <code>organizations</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/47929">#47929</a> User profile multiselect options not highlighted as selected in dropdown <code>admin/ui</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/47955">#47955</a> IdentityProviderAuthenticator creates an infinite redirect loop when an IdP returns an error (e.g. access_denied) and the login was initiated with kc_idp_hint <code>identity-brokering</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/48015">#48015</a> Missing explicit docs anchor for organizations <code>docs</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/48032">#48032</a> Endpoint Response Text during Bootstrap contains Typo: Boostrap <code>dist/quarkus</code></li> </ul>

</div>

<div> <h2>Highlights</h2> <div class="paragraph"> <p>This release features new capabilities for users and administrators of Keycloak. The highlights of this release are:</p> </div> <div class="ulist"> <ul> <li> <p><strong>JWT Authorization Grant</strong>, enabling external-to-internal token exchange using externally signed JWT assertions.</p> </li> <li> <p><strong>Federated client authentication</strong>, eliminating the need to manage individual client secrets in Keycloak.</p> </li> <li> <p><strong>Workflows</strong>, enabling administrators to automate realm administrative tasks such as user and client lifecycle management.</p> </li> <li> <p><strong>Zero-downtime patch releases</strong>, allowing rolling updates within a minor release stream without service downtime.</p> </li> <li> <p>The <strong>Keycloak Test Framework</strong>, replacing the previous Arquillian-based solution.</p> </li> </ul> </div> <div class="paragraph"> <p>All of these features are now fully supported and no longer in preview. Read on to learn more about each new feature. If you are upgrading from a previous release, <a href="https://www.keycloak.org/docs/latest/upgrading/index.html">also review the changes listed in the upgrading guide</a>.</p> </div> <div class="sect2"> <h3 id="security_and_standards">Security and Standards</h3> <div class="sect3"> <h4 id="_jwt_authorization_grant_supported">JWT Authorization Grant (supported)</h4> <div class="paragraph"> <p>JWT Authorization Grant (<a href="https://datatracker.ietf.org/doc/html/rfc7523">RFC 7523</a>) is designed to implement external-to-internal token exchange use cases. This grant allows using externally signed JWT assertions to request OAuth 2.0 access tokens.</p> </div> <div class="paragraph"> <p>In this release, JWT Authorization Grant is promoted from preview to supported. See the <a href="https://www.keycloak.org/securing-apps/jwt-authorization-grant">JWT Authorization Grant guide</a> for additional details.</p> </div> </div> <div class="sect3"> <h4 id="_federated_client_authentication_supported">Federated client authentication (supported)</h4> <div class="paragraph"> <p>Federated client authentication allows clients to leverage existing credentials once a trust relationship with another issuer exists. It eliminates the need to assign and manage individual secrets for each client in Keycloak.</p> </div> <div class="paragraph"> <p>Federated client authentication is now promoted to supported, including support for client assertions issued by external OpenID Connect identity providers and Kubernetes Service Accounts.</p> </div> <div class="paragraph"> <p>Since the OAuth SPIFFE Client Authentication specification is still in draft status, this feature remains a preview feature in Keycloak.</p> </div> </div> <div class="sect3"> <h4 id="_new_guide_about_demonstrating_proof_of_possession_dpop">New guide about Demonstrating Proof-of-Possession (DPoP)</h4> <div class="paragraph"> <p>A new guide for OAuth 2.0 Demonstrating Proof-of-Possession (DPoP) in the Securing applications Guides provides information on how to mitigate the risk of stolen tokens by making tokens sender-constrained.</p> </div> <div class="paragraph"> <p>See <a href="https://www.keycloak.org/nightly/securing-apps/dpop">Securing applications with DPoP</a> for more details.</p> </div> </div> <div class="sect3"> <h4 id="_identity_brokering_apis_v2_preview">Identity Brokering APIs V2 (preview)</h4> <div class="paragraph"> <p>A new preview version 2 for the Identity Brokering APIs is introduced in this release. When brokering is used during the authentication process, Keycloak allows you to store tokens and responses issued by the external Identity Provider. Applications can call a specific endpoint to retrieve those tokens, which, in turn, can be used to get extra user information or invoke endpoints in the external trust domain. The new version improves the token retrieval endpoint to substitute the internal to external Token Exchange (use case for the <a href="https://www.keycloak.org/securing-apps/token-exchange#_legacy-token-exchange">legacy Token Exchange V1</a>).</p> </div> <div class="paragraph"> <p>For more information, see the chapter <a href="https://www.keycloak.org/docs/26.6.0/server_development/#_identity-brokering-apis">Identity Brokering APIs</a> in the Server Developer Guide.</p> </div> </div> <div class="sect3"> <h4 id="_step_up_authentication_for_saml_preview">Step-up authentication for SAML (preview)</h4> <div class="paragraph"> <p>The feature <code>step-up-authentication-saml</code> extends the step-up authentication to include the SAML protocol and clients. This feature is in preview mode. Additional information is available in the <a href="https://www.keycloak.org/docs/26.6.0/server_admin/#_step-up-authentication-saml">Server Administration Guide</a>.</p> </div> </div> <div class="sect3"> <h4 id="_oauth_client_id_metadata_document_experimental">OAuth Client ID Metadata Document (experimental)</h4> <div class="paragraph"> <p><a href="https://www.ietf.org/archive/id/draft-ietf-oauth-client-id-metadata-document-01.html">OAuth Client ID Metadata Document (CIMD)</a> is an emerging standard that defines a JSON document format for describing OAuth 2.0 client metadata. Since version 2025-11-25, the Model Context Protocol (MCP) requires an authorization server to comply with CIMD. Keycloak now includes experimental support for CIMD, allowing it to serve as an authorization server for MCP version 2025-11-25 or later.</p> </div> <div class="paragraph"> <p>See <a href="https://www.keycloak.org/securing-apps/mcp-authz-server">Integrating with Model Context Protocol (MCP)</a> for the updated guide including CIMD.</p> </div> <div class="paragraph"> <p>Many thanks to <a href="https://github.com/tnorimat">Takashi Norimatsu</a> for the contribution.</p> </div> </div> </div> <div class="sect2"> <h3 id="_administration">Administration</h3> <div class="sect3"> <h4 id="_workflows_supported">Workflows (supported)</h4> <div class="paragraph"> <p>Workflows allow administrators to automate and orchestrate realm administrative tasks, bringing key capabilities of Identity Governance and Administration (IGA) to Keycloak. By defining workflows in YAML format, you can automate the lifecycle of realm resources such as users and clients based on events, conditions, and schedules.</p> </div> <div class="paragraph"> <p>In this release, Workflows is promoted from preview to supported. This release also includes new built-in steps, a troubleshooting guide, and various improvements to the workflow engine.</p> </div> <div class="paragraph"> <p>For more details, see the <a href="https://www.keycloak.org/docs/26.6.0/server_admin/#_managing_workflows">Managing workflows</a> chapter in the Server Administration Guide.</p> </div> </div> <div class="sect3"> <h4 id="_organization_groups">Organization groups</h4> <div class="paragraph"> <p>Organizations now support isolated group hierarchies, allowing each organization to manage its own teams and departments without naming conflicts across the realm. This update includes Identity Provider mappers to automatically assign federated users to organization groups based on external claims. Group membership is automatically included in OIDC tokens and SAML assertions when an organization context is requested.</p> </div> <div class="paragraph"> <p>For more details, see the <a href="https://www.keycloak.org/docs/26.6.0/server_admin/#_managing_groups">Managing organization groups</a> guide.</p> </div> </div> <div class="sect3"> <h4 id="_new_groups_scope_for_user_membership_changes">New Groups scope for user membership changes</h4> <div class="paragraph"> <p>Fine-Grained Admin Permissions (FGAP) now includes a new <code>Groups</code> scope: <code>manage-membership-of-members</code>.</p> </div> <div class="paragraph"> <p>This scope is now used as the group-side bridge for evaluating user-side <code>manage-group-membership</code> permissions based on a user&#8217;s current group memberships. The existing <code>manage-membership</code> scope keeps its current behavior for target group membership management operations.</p> </div> </div> <div class="sect3"> <h4 id="_looking_up_client_secrets_via_the_vault_spi">Looking up client secrets via the Vault SPI</h4> <div class="paragraph"> <p>Secrets for clients can now be managed and looked up by the Vault SPI.</p> </div> <div class="paragraph"> <p>Thank you to <a href="https://github.com/tsaarni">Tero Saarni</a> for contributing this change.</p> </div> </div> <div class="sect3"> <h4 id="_forcing_password_change_for_ldap_users">Forcing password change for LDAP users</h4> <div class="paragraph"> <p>There is now initial support for LDAP password policy control. The support is limited to prompting users to update their password when the LDAP server indicates that the password must be changed. Previously, Keycloak let the user in and ignored the mandatory password reset. There is a new optional setting &#8220;Enable LDAP password policy&#8221; in the LDAP advanced settings to enable this.</p> </div> <div class="paragraph"> <p>Thank you to <a href="https://github.com/tsaarni">Tero Saarni</a> for contributing this change.</p> </div> </div> </div> <div class="sect2"> <h3 id="_configuring_and_running">Configuring and Running</h3> <div class="sect3"> <h4 id="_java_25_support">Java 25 support</h4> <div class="paragraph"> <p>Keycloak now supports running with OpenJDK 25. The server container image continues to use OpenJDK 21 for now to support FIPS mode. For details, see the note in the FIPS guide.</p> </div> </div> <div class="sect3"> <h4 id="_zero_downtime_patch_releases_supported">Zero-downtime patch releases (supported)</h4> <div class="paragraph"> <p>Zero-downtime patch releases allow you to perform rolling updates when upgrading to a newer patch version within the same <code>major.minor</code> release stream without service downtime.</p> </div> <div class="paragraph">

…(truncated)

<div>

<h2>Upgrading</h2> <p>Before upgrading refer to <a href="https://www.keycloak.org/docs/latest/upgrading/#migration-changes">the migration guide</a> for a complete list of changes.</p>

<h2>All resolved issues</h2>

<h3>Security fixes</h3> <ul> <li><a href="https://github.com/keycloak/keycloak/issues/45493">#45493</a> CVE-2025-14083 keycloak-server: Keycloak: Improper Access Control in Admin REST API leads to information disclosure <code>admin/api</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/45569">#45569</a> CVE-2026-1002 - io.vertx/vertx-core: static handler component cache can be manipulated to deny the access to static files </li> <li><a href="https://github.com/keycloak/keycloak/issues/47069">#47069</a> CVE-2026-3429 Improper Access Control for LoA During Credential Deletion <code>account/api</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/47716">#47716</a> CVE-2026-4634 Keycloak Application-Level DoS via Scope Processing </li> <li><a href="https://github.com/keycloak/keycloak/issues/47717">#47717</a> CVE-2026-4636 UMA Policy Resource Injection Allows Unauthorized Cross-User Permission Grants </li> <li><a href="https://github.com/keycloak/keycloak/issues/47718">#47718</a> CVE-2026-3872 Redirect URI validation bypass via ..;/ path traversal in OIDC auth endpoint </li> <li><a href="https://github.com/keycloak/keycloak/issues/47719">#47719</a> CVE-2026-4282 Privilege escalation via forged authorization codes due to SingleUseObjectProvider isolation flaw </li> </ul>

<h3>Enhancements</h3> <ul> <li><a href="https://github.com/keycloak/keycloak/issues/46631">#46631</a> Upgrade to Quarkus 3.27.3 <code>dist/quarkus</code></li> </ul>

<h3>Bugs</h3> <ul> <li><a href="https://github.com/keycloak/keycloak/issues/45204">#45204</a> Call without Host header throws uncaught error <code>core</code></li> </ul>

</div>

<div>

<h2>Upgrading</h2> <p>Before upgrading refer to <a href="https://www.keycloak.org/docs/latest/upgrading/#migration-changes">the migration guide</a> for a complete list of changes.</p>

<h2>All resolved issues</h2>

<h3>Security fixes</h3> <ul> <li><a href="https://github.com/keycloak/keycloak/issues/45645">#45645</a> CVE-2026-1180 - Blind Server-Side Request Forgery (SSRF) in Keycloak OIDC Dynamic Client Registration via jwks_uri <code>oidc</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/45647">#45647</a> CVE-2026-1035 - Keycloak Refresh Token Reuse Bypass via TOCTOU Race Condition <code>oidc</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/45650">#45650</a> CVE-2025-14777 - Keycloak IDOR in realm client creating/deleting </li> <li><a href="https://github.com/keycloak/keycloak/issues/45653">#45653</a> CVE-2025-14082 keycloak-server: Keycloak Admin REST API: Improper Access Control leads to sensitive role metadata information disclosure </li> <li><a href="https://github.com/keycloak/keycloak/issues/46719">#46719</a> CVE-2026-3121 - Keycloak: Privilege escalation via manage-clients permission </li> <li><a href="https://github.com/keycloak/keycloak/issues/46723">#46723</a> CVE-2026-3190 - Information Disclosure via improper role enforcement in UMA 2.0 Protection API <code>core</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/46922">#46922</a> CVE-2026-3911 Keycloak: Information disclosure of disabled user attributes via administrative endpoint <code>user-profile</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/47062">#47062</a> CVE-2026-2366 Authorization Bypass: Unprivileged tokens can enumerate user organization memberships <code>organizations</code></li> </ul>

<h3>Bugs</h3> <ul> <li><a href="https://github.com/keycloak/keycloak/issues/45889">#45889</a> Federated user disabled when external DB unavailable, never re-enabled <code>storage</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/46239">#46239</a> AUTH_SESSION_ID cookie reuse causes cross-user session contamination on re-authentication <code>authentication</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/46296">#46296</a> UsersResource.search briefRepresentation started to return user attributes <code>admin/api</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/46379">#46379</a> Unexpected error when logging out with offline session and external IDP <code>oidc</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/46459">#46459</a> Operator-built DB config: targetServerType=primary not applied / connection validation not working after master-replica failover (26.5.0) <code>operator</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/46588">#46588</a> Partial LDAP sync duration does not follow the defined value in user federation <code>ldap</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/46605">#46605</a> 26.5.4 startup regression with many realms: RealmCacheSession.prepareCachedRealm() scans master admin role composites per realm (O(N²)) <code>core</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/46656">#46656</a> Em-Hyphens in SPI options on cache configuration page <code>docs</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/46663">#46663</a> JGroups bind port configuration ignored when --cache-embedded-network-bind-port set <code>infinispan</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/46669">#46669</a> SPIFFE Client assertion throws a NullPointerException if no client is found <code>token-exchange</code></li> <li><a href="https://github.com/keycloak/keycloak/issues/47079">#47079</a> Do not allow fetching organizations of a member if not a member of the current organization <code>organizations</code></li> </ul>

</div>