- Issued:
- 2026-08-05
- Updated:
- 2026-08-05
RHSA-2026:50848 - Important: Red Hat build of Keycloak 26.6.5 Security Update
Synopsis
Important: Red Hat build of Keycloak 26.6.5 Security Update
Type/Severity
Security Advisory: Important
Topic
New Red Hat build of Keycloak 26.6.5 packages are available from the Customer Portal
Description
Red Hat build of Keycloak 26.6.5 is a standalone server, based on the Keycloak project, that provides authentication and standards-based single sign-on capabilities for web and mobile applications.
Security fixes:
- Authorization Bypass vulnerability in the admin-ui-ext bulk role-mapping-delete endpoints of Keycloak (CVE-2026-11986)
- Admin UI extension brute-force-user endpoint bypasses FGAPv2 user view restrictions (CVE-2026-14209)
- FGAP v2 client scope assignment bypass via ClientResource (CVE-2026-14614)
- FGAP v2 parent group children endpoint bypasses per-child view permission filter (CVE-2026-14615)
- DCR protocol mapper type-swap policy bypass allows privilege escalation (CVE-2026-15572)
- Authorization bypass via unnormalized URI matching in PathMatcher (CVE-2026-15573)
- LDAP entry-DN user search bypasses configured users DN boundary (CVE-2026-16071)
- Unbounded metric cardinality in user event metrics via request-controlled error text (CVE-2026-16100)
- Default DCR policy allows role forgery via User Property mappers (CVE-2026-16102)
- Quarkus REST - Unbounded multipart MIME part-header accumulation allows remote OOM denial of service (CVE-2026-16308)
- SAML IdP-initiated broker login bypasses link-only restriction (CVE-2026-16442)
- SAML broker metadata import disables response signature validation (CVE-2026-16443)
- Denial of Service via specially crafted gRPC requests (CVE-2026-40983)
- Denial of Service via specially crafted HTTP requests (CVE-2026-40984)
- Arbitrary code execution via PolymorphicTypeValidator bypass (CVE-2026-54512)
- Security bypass allows arbitrary code execution (CVE-2026-54513)
- HTTP Parameter Pollution in OIDC redirect URI allows response parameter duplication - #GHI-604 (CVE-2026-9689)
- Security policy bypass in JWE-encrypted request object processing (CVE-2026-9793)
- Brute-force protection bypass in CIBA flow (CVE-2026-9798)
Solution
Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on.
Affected Products
| Product | Version | Arch |
|---|---|---|
| Red Hat build of Keycloak | Text-only Advisories | x86_64 |
Fixes
(none)
CVEs
- CVE-2026-9689
- CVE-2026-9793
- CVE-2026-9798
- CVE-2026-11986
- CVE-2026-14209
- CVE-2026-14614
- CVE-2026-14615
- CVE-2026-15572
- CVE-2026-15573
- CVE-2026-16071
- CVE-2026-16100
- CVE-2026-16102
- This content is not included.CVE-2026-16308
- CVE-2026-16442
- CVE-2026-16443
- This content is not included.CVE-2026-40983
- This content is not included.CVE-2026-40984
- This content is not included.CVE-2026-54512
- This content is not included.CVE-2026-54513
References
Additional information
- The Red Hat security contact is This content is not included.secalert@redhat.com. More contact details at Security Contacts and Procedures.
- Offline Security Data data is available for integration with other systems. See Offline Security Data API to get started.