Issued:
2026-08-05
Updated:
2026-08-05

RHSA-2026:50846 - Important: Red Hat build of Keycloak 26.4.14 Security Update


Synopsis

Important: Red Hat build of Keycloak 26.4.14 Security Update

Type/Severity

Security Advisory: Important

Topic

New Red Hat build of Keycloak 26.4.14 packages are available from the Customer Portal

Description

Red Hat build of Keycloak 26.4.14 is a standalone server, based on the Keycloak project, that provides authentication and standards-based single sign-on capabilities for web and mobile applications.

Security fixes:

  • Admin UI extension brute-force-user endpoint bypasses FGAPv2 user view restrictions (CVE-2026-14209)
  • FGAP v2 client scope assignment bypass via ClientResource (CVE-2026-14614)
  • FGAP v2 parent group children endpoint bypasses per-child view permission filter (CVE-2026-14615)
  • DCR protocol mapper type-swap policy bypass allows privilege escalation (CVE-2026-15572)
  • Authorization bypass via unnormalized URI matching in PathMatcher (CVE-2026-15573)
  • LDAP entry-DN user search bypasses configured users DN boundary (CVE-2026-16071)
  • Default DCR policy allows role forgery via User Property mappers (CVE-2026-16102)
  • Quarkus REST - Unbounded multipart MIME part-header accumulation allows remote OOM denial of service (CVE-2026-16308)
  • SAML IdP-initiated broker login bypasses link-only restriction (CVE-2026-16442)
  • SAML broker metadata import disables response signature validation (CVE-2026-16443)
  • Privilege escalation through hardcoded role mapper injection (CVE-2026-4629)
  • Arbitrary code execution via PolymorphicTypeValidator bypass (CVE-2026-54512)
  • Security bypass allows arbitrary code execution (CVE-2026-54513)
  • HTTP Parameter Pollution in OIDC redirect URI allows response parameter duplication - #GHI-604 (CVE-2026-9689)
  • Security policy bypass in JWE-encrypted request object processing (CVE-2026-9793)
  • Brute-force protection bypass in CIBA flow (CVE-2026-9798)
  • Authorization bypass via incorrect URI comparison (CVE-2026-9800)

Solution

Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on.

Affected Products

ProductVersionArch
Red Hat build of KeycloakText-only Advisoriesx86_64

Fixes

(none)

CVEs

References


Additional information