Keycloak 26.7.5 released
September 30 2026
To download the release go to Keycloak downloads.
Upgrading
Before upgrading refer to the migration guide for a complete list of changes.
All resolved issues
Security fixes
- #50996 [CVE-2026-16103] Incomplete fix for CVE-2026-9798 (Keycloak CIBA brute-force lockout bypass at token redemption) oidc
- #51278 [CVE-2026-18206] Client policy source-host wildcard domains match non-subdomain suffixes oidc
- #51280 [CVE-2026-18203] Group policy child-extension matches sibling group path prefixes authorization-services
- #51281 [CVE-2026-18207] Source-group condition matches duplicate group names and can skip negative-logic enforcement oidc
- #51284 [CVE-2026-18208] Inactive out-of-audience introspection responses can include a signed JWT claim oidc
- #51285 [CVE-2026-18211] Secure-client-uris localhost exception accepts localhost-prefixed attacker domains oidc
- #51781 [CVE-2026-18217] SAML Redirect Binding Parameter Pollution saml
- #52531 CVE-2025-66021 com.googlecode.owasp-java-html-sanitizer:owasp-java-html-sanitizer dependencies
- #52692 [CVE-2026-89298] Confidential client secret disclosed to view-clients role via Client Registration GET oidc
- #52783 [CVE-2026-88770] Device Authorization Grant issues tokens to brute-force-locked accounts (sibling of CVE-2026-9798) oidc
- #52888 CVE-2026-84939 org.freemarker:freemarker
- #52972 CVE-2026-8798 org.bouncycastle:bc-fips dependencies
- #52974 CVE-2026-13505 org.bouncycastle:bc-fips dependencies
- #53074 [CVE-2026-93999] Keycloak 26.7.2: token-exchange refresh continues issuing tokens for a disabled audience client token-exchange
Weaknesses
- #51340 DCR: Registration access token allows protocol switch from OIDC to SAML oidc
- #53024 check-licenses.sh: shell injection via source of dependency pom.properties
Enhancements
- #52357 Upgrade to Quarkus 3.33.4 dist/quarkus
Bugs
- #50739 keycloak 26.7.0 sha1 file is missing dist/quarkus
- #50903 Missing input length validation on username field causes outsized log generation in /login-actions/authenticate authentication
- #51065 Flaky test: org.keycloak.testsuite.oauth.ClientAuthPostMethodTest#testPostAuthenticationNotAllowedWhenBasicRequested ci
- #51067 Flaky test: org.keycloak.testsuite.oauth.ClientAuthPostMethodTest#testBasicAuthenticationNotAllowedWhenPostRequested ci
- #51304 Upgrade to 26.7.0 crashes under several tested scenarios. LazyInitializationException on non-deterministic getRealmsStream() order after DB dump/restore. infinispan
- #51761 PAR request URI lifespan is used as a hard cap on interactive login duration oidc
- #51778 [quarkus-next] BouncyCastle 1.85 breaks SAML client creation when client ID exceeds 64 characters dist/quarkus
- #52033 Improve retrieval of large read-only resources via admin API storage
- #52088 New Infinispan node joining the cluster becomes a command target/coordinator before its cache components are ready - ISPN000136 failures during Keycloak rolling restarts infinispan
- #52153 DEBUG logging breaks persistent client session locking storage
- #52193 Identity Provider Mappers - organization group targets do not resolve organizations
- #52257 Event listeners receive the wrong event type when an EventBuilder is reused (e.g. FEDERATED_IDENTITY_LINK is logged and emailed as LOGIN) core
- #52309 Admin Permissions filtering is applied to organization lookups during end-user authentication organizations
- #52327 surefire-junit-platform not cached, causing intermittent test failures in CI ci
- #52329 Flaky test: FlowTest.testRemoveExecutionSubflow fails with stale DELETE admin event testsuite
- #52331 Flaky SCIM FilterTest.testFilterGroupsByMetaTimestamps due to same-millisecond timing saml
- #52415 Flaky test: WebAuthnTransportLocaleTest.localizationTransportInternal fails with "Cannot logout user" testsuite
- #52423 Flaky test: MySQLDistTest fails with "process hasn't exited" on slow CI runners testsuite
- #52428 Flaky test: AttackDetectionResourceTest due to DefaultBlockingBruteForceProtector concurrent login blocking authentication
- #52433 Flaky test: registration-policies.spec.ts kebab menu "Delete" item not found after toggle click testsuite
- #52435 Flaky test: timeout.spec.ts fails with "fetch failed" due to server not ready and hardcoded port testsuite
- #52460 Remove azure-cli version pin after runner image update removes apt source ci
- #52487 Managing Identity Providers in the admin UI now requires client roles in the realm admin/ui
- #52490 Flaky Admin UI E2E test: "Should show items on next page" in scope.spec.ts ci
- #52493 AuroraDB IT - Create EC2 runner instance fails: RHEL 9.4 AMI deregistered ci
- #52712 WebAuthnPolicyComplianceTest.replayedCredentialRegistration is flaky due to missing sync point authentication
- #52716 Flaky CI: junit-jupiter-engine not in Maven cache causes transient test failures ci
- #52868 Flaky test: RecoveryAuthnCodesAuthenticatorTest#test07SetupRecoveryAuthnCodes on Chrome testsuite
- #53054 ServerConfigClassOrderer comparator violates Comparable contract causing flaky CI failures testsuite
- #53069 Format string mismatches in logging statements cause silent argument loss and potential MissingFormatArgumentException core