Keycloak 26.7.2 released
August 19 2026
To download the release go to Keycloak downloads.
Upgrading
Before upgrading refer to the migration guide for a complete list of changes.
All resolved issues
Security fixes
- #49570 CVE-2026-45292 OpenTelemetry Java SDK has Unbounded Memory Allocation in W3C Baggage Propagation dependencies
- #50616 [CVE-2026-14613] Keycloak 26.6.3 Fine-Grained Admin Permissions Bypass via Role Groups Endpoint admin/fine-grained-permissions
- #50955 [CVE-2026-59888 and CVE-2026-59889] Upgrade jackson-databind to 2.21.5 to fix
- #50966 [CVE-2026-15945] Group hierarchy search discloses hidden parent groups under FGAP v2 admin/fine-grained-permissions
- #51145 [CVE-2026-17048] Keycloak Admin REST API Leaks Vault-Resolved Rotated Client Secrets oidc
- #51832 CVE-2026-15571 Predictable account-linking hash enables account takeover via malicious oidc client
- #51833 CVE-2026-18963 Unauthenticated account takeover via reset-credentials flow bypass
Weaknesses
- #50844 show-config prints the vault keystore password in cleartext dist/quarkus
Enhancements
- #51344 Upgrade to Quarkus 3.33.3.1
Bugs
- #50751 Password denylist: false fpp warning on startup with large pre-computed .bloom file authentication
- #50849 Correct SCIM name.formated scim
- #50855 Rotated client secret remains valid when the feature is disabled oidc
- #51054 Invalid redirect URI on logout from pages with sub-tab hash fragments admin/ui
- #51061 Parameterized UserPropertyMapper exposes target user attributes without permission check core
- #51087 Passkey icons use wrong color variant when realm disables dark mode authentication/webauthn
- #51088 Verify email not working in incognito browser tab after Keycloak restart authentication
- #51131 Warning "Proactive closing of the session was missed - refinements are needed to TransactionSessionHandler related logic" appears core
- #51154 Upgrade to 26.7.0 fails with preview features as the stateless cluster provider captures a null NodeInfo before postInit infinispan
- #51164 WebAuthn tests are being skipped in Github workflows workflows
- #51182 Large HTTP/2 request headers are rejected with a bare 500 and no log; same request works over HTTP/1.1 dist/quarkus
- #51323 Custom realm-level role named admin cannot be updated in non-master realms after Keycloak 26.7.0 admin/rbac
- #51331 Adding org member fails with 500 with stateless:v1 feature enabled organizations
- #51407 The dist for Java API docs is empty docs
- #51449 Incorrect query parameter name for "max"
- #51476 Invalid link for https://www.ietf.org/rfc/rfc4559.txt docs