Keycloak 26.7.1 released
August 05 2026
To download the release go to Keycloak downloads.
Upgrading
Before upgrading refer to the migration guide for a complete list of changes.
All resolved issues
Security fixes
- #49429 [CVE-2026-9793] JWE request object bypasses requestObjectSignatureAlg enforcement oidc
- #50445 [CVE-2026-4629] Privilege escalation via hardcoded role mapper injection in manage-clients admin/api
- #50569 [CVE-2026-14209] Keycloak Admin UI Extension `brute-force-user` User Disclosure via `search=id:` under FGAP v2 admin/fine-grained-permissions
- #50615 [CVE-2026-14614] Keycloak 26.6.3 Fine-Grained Admin Permissions Bypass in Client Scope Assignment admin/fine-grained-permissions
- #50617 [CVE-2026-14615] FGAP v2 parent group children endpoint bypasses per-child view permission filter admin/fine-grained-permissions
Bugs
- #50719 WebAuthn authenticator attachment policy is bypassed when the client omits the attachment field authentication/webauthn
- #50750 Clustering test broken in 26.7 release branch ci
- #50836 Kustomize cluster-wide faulty Role&RoleBinding operator
- #50850 New Password is commited when multiple Password Reset is detected authentication
- #50882 500 when client requests `organization` scope with it already set to `Default` authentication
- #50928 IllegalFormatConversionException in LiquibaseDBLockProviderFactory and wrong time conversion core