Issued:
2026-08-05
Updated:
2026-08-05

RHSA-2026:50848 - Important: Red Hat build of Keycloak 26.6.5 Security Update


Synopsis

Important: Red Hat build of Keycloak 26.6.5 Security Update

Type/Severity

Security Advisory: Important

Topic

New Red Hat build of Keycloak 26.6.5 packages are available from the Customer Portal

Description

Red Hat build of Keycloak 26.6.5 is a standalone server, based on the Keycloak project, that provides authentication and standards-based single sign-on capabilities for web and mobile applications.

Security fixes:

  • Authorization Bypass vulnerability in the admin-ui-ext bulk role-mapping-delete endpoints of Keycloak (CVE-2026-11986)
  • Admin UI extension brute-force-user endpoint bypasses FGAPv2 user view restrictions (CVE-2026-14209)
  • FGAP v2 client scope assignment bypass via ClientResource (CVE-2026-14614)
  • FGAP v2 parent group children endpoint bypasses per-child view permission filter (CVE-2026-14615)
  • DCR protocol mapper type-swap policy bypass allows privilege escalation (CVE-2026-15572)
  • Authorization bypass via unnormalized URI matching in PathMatcher (CVE-2026-15573)
  • LDAP entry-DN user search bypasses configured users DN boundary (CVE-2026-16071)
  • Unbounded metric cardinality in user event metrics via request-controlled error text (CVE-2026-16100)
  • Default DCR policy allows role forgery via User Property mappers (CVE-2026-16102)
  • Quarkus REST - Unbounded multipart MIME part-header accumulation allows remote OOM denial of service (CVE-2026-16308)
  • SAML IdP-initiated broker login bypasses link-only restriction (CVE-2026-16442)
  • SAML broker metadata import disables response signature validation (CVE-2026-16443)
  • Denial of Service via specially crafted gRPC requests (CVE-2026-40983)
  • Denial of Service via specially crafted HTTP requests (CVE-2026-40984)
  • Arbitrary code execution via PolymorphicTypeValidator bypass (CVE-2026-54512)
  • Security bypass allows arbitrary code execution (CVE-2026-54513)
  • HTTP Parameter Pollution in OIDC redirect URI allows response parameter duplication - #GHI-604 (CVE-2026-9689)
  • Security policy bypass in JWE-encrypted request object processing (CVE-2026-9793)
  • Brute-force protection bypass in CIBA flow (CVE-2026-9798)

Solution

Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on.

Affected Products

ProductVersionArch
Red Hat build of KeycloakText-only Advisoriesx86_64

Fixes

(none)

CVEs

References


Additional information