26.7.1
Checked 1 Oct 2026. BlackTree preserves the last verified facts if a later source check is temporarily unavailable.
Open the official publisher sourcePUBLISHER UPDATE · KEYCLOAK-26.7.1
26.7.1
Scope: Keycloak. This update record adds version, fix and known-issue context. Its publication date is not a lifecycle boundary.
Upgrading Before upgrading refer to the migration guide for a complete list of changes. All resolved issues Security fixes #49429 [ CVE-2026-9793 ] JWE request object bypasses requestObjectSignatureAlg enforcement oidc #50445 [ CVE-2026-4629 ] Privilege escalation via hardcoded role mapper injection in manage-clients admin/api #50569 [ CVE-2026-14209 ] Keycloak Admin UI Extension `brute-force-user` User Disclosure via `search=id:` under FGAP v2 admin/fine-grained-permissions #50615 [ CVE-2026-14614 ] Keycloak 26.6.3 Fine-Grained Admin Permissions Bypass in Client Scope Assignment admin/fine-grained-permissions #50617 [ CVE-2026-14615 ] FGAP v2 parent group children endpoint bypasses per-child view permission filter admin/fine-grained-permissions #51467 CVE-2026-15573 Authorization bypass via unnormalized uri matching in pathmatcher #51468 CVE-2026-15572 DCR protocol mapper type-swap policy bypass allows privilege escalation #51469 CVE-2026-16100 Unbounded metric cardinality in user event metrics via request-controlled error text #51470 CVE-2026-16442 SAML idp-initiated broker login bypasses link-only restriction #51471 CVE-2026-16443 SAML broker metadata import disables response signature validation #51472 CVE-2026-16071 LDAP entry-dn user search bypasses configured users dn boundary #51473 CVE-2026-16102 Default DCR policy allows role forgery via user property mappers Bugs #50719 WebAuthn authenticator attachment policy is bypassed when the client omits the attachment field authentication/webauthn #50750 Clustering test broken in 26.7 release branch ci #50836 Kustomize cluster-wide faulty Role&RoleBinding operator #50850 New Password is commited when multiple Password Reset is detected authentication #50882 500 when client requests `organization` scope with it already set to `Default` authentication #50928 IllegalFormatConversionException in LiquibaseDBLockProviderFactory and wrong time conversion core
Not stated. The verified publisher record does not contain a known-issues statement.
Review the official publisher document before deployment.
Checked 1 Oct 2026. BlackTree preserves the last verified facts if a later source check is temporarily unavailable.
Open the official publisher source