Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Lifecycle catalogue
RELEASE NOTESKEYCLOAKVERIFIED

PUBLISHER UPDATE · KEYCLOAK-26.7.2

KEYCLOAK-26.7.2 release notes and known issues

26.7.2

Scope: Keycloak. This update record adds version, fix and known-issue context. Its publication date is not a lifecycle boundary.

Summary

Upgrading Before upgrading refer to the migration guide for a complete list of changes. All resolved issues Security fixes #49570 CVE-2026-45292 OpenTelemetry Java SDK has Unbounded Memory Allocation in W3C Baggage Propagation dependencies #50616 [ CVE-2026-14613 ] Keycloak 26.6.3 Fine-Grained Admin Permissions Bypass via Role Groups Endpoint admin/fine-grained-permissions #50955 [ CVE-2026-59888 and CVE-2026-59889 ] Upgrade jackson-databind to 2.21.5 to fix #50966 [ CVE-2026-15945 ] Group hierarchy search discloses hidden parent groups under FGAP v2 admin/fine-grained-permissions #51145 [ CVE-2026-17048 ] Keycloak Admin REST API Leaks Vault-Resolved Rotated Client Secrets oidc #51832 CVE-2026-15571 Predictable account-linking hash enables account takeover via malicious oidc client #51833 CVE-2026-18963 Unauthenticated account takeover via reset-credentials flow bypass Weaknesses #50844 show-config prints the vault keystore password in cleartext dist/quarkus Enhancements #51344 Upgrade to Quarkus 3.33.3.1 Bugs #50751 Password denylist: false fpp warning on startup with large pre-computed .bloom file authentication #50849 Correct SCIM name.formated scim #50855 Rotated client secret remains valid when the feature is disabled oidc #51054 Invalid redirect URI on logout from pages with sub-tab hash fragments admin/ui #51061 Parameterized UserPropertyMapper exposes target user attributes without permission check core #51087 Passkey icons use wrong color variant when realm disables dark mode authentication/webauthn #51088 Verify email not working in incognito browser tab after Keycloak restart authentication #51131 Warning "Proactive closing of the session was missed - refinements are needed to TransactionSessionHandler related logic" appears core #51154 Upgrade to 26.7.0 fails with preview features as the stateless cluster provider captures a null NodeInfo before postInit infinispan #51164 WebAuthn tests are being skipped in Github workflows workflows #51182 Large HTTP/2 request headers are rejected with a bare 500 and no log; same request works over HTTP/1.1 dist/quarkus #51323 Custom realm-level role named admin cannot be updated in non-master realms after Keycloak 26.7.0 admin/rbac #51331 Adding org member fails with 500 with stateless:v1 feature enabled organizations #51407 The dist for Java API docs is empty docs #51449 Incorrect query parameter name for "max" #51476 Invalid link for https://www.ietf.org/rfc/rfc4559.txt docs

Improvements and security content

  • Upgrading Before upgrading refer to the migration guide for a complete list of changes. All resolved issues Security fixes #49570 CVE-2026-45292 OpenTelemetry Java SDK has Unbounded Memory Allocation in W3C Baggage Propagation dependencies #50616 [ CVE-2026-14613 ] Keycloak 26.6.3 Fine-Grained Admin Permissions Bypass via Role Groups Endpoint admin/fine-grained-permissions #50955 [ CVE-2026-59888 and CVE-2026-59889 ] Upgrade jackson-databind to 2.21.5 to fix #50966 [ CVE-2026-15945 ] Group hierarchy search discloses hidden parent groups under FGAP v2 admin/fine-grained-permissions #51145 [ CVE-2026-17048 ] Keycloak Admin REST API Leaks Vault-Resolved Rotated Client Secrets oidc #51832 CVE-2026-15571 Predictable account-linking hash enables account takeover via malicious oidc client #51833 CVE-2026-18963 Unauthenticated account takeover via reset-credentials flow bypass Weaknesses #50844 show-config prints the vault keystore password in cleartext dist/quarkus Enhancements #51344 Upgrade to Quarkus 3.33.3.1 Bugs #50751 Password denylist: false fpp warning on startup with large pre-computed .bloom file authentication #50849 Correct SCIM name.formated scim #50855 Rotated client secret remains valid when the feature is disabled oidc #51054 Invalid redirect URI on logout from pages with sub-tab hash fragments admin/ui #51061 Parameterized UserPropertyMapper exposes target user attributes without permission check core #51087 Passkey icons use wrong color variant when realm disables dark mode authentication/webauthn #51088 Verify email not working in incognito browser tab after Keycloak restart authentication #51131 Warning "Proactive closing of the session was missed - refinements are needed to TransactionSessionHandler related logic" appears core #51154 Upgrade to 26.7.0 fails with preview features as the stateless cluster provider captures a null NodeInfo before postInit infinispan #51164 WebAuthn tests are being skipped in Github workflows workflows #51182 Large HTTP/2 request headers are rejected with a bare 500 and no log; same request works over HTTP/1.1 dist/quarkus #51323 Custom realm-level role named admin cannot be updated in non-master realms after Keycloak 26.7.0 admin/rbac #51331 Adding org member fails with 500 with stateless:v1 feature enabled organizations #51407 The dist for Java API docs is empty docs #51449 Incorrect query parameter name for "max" #51476 Invalid link for https://www.ietf.org/rfc/rfc4559.txt docs

Known issues

Publisher statement

Not stated. The verified publisher record does not contain a known-issues statement.

Affected products and versions

Products

  • Keycloak

Affected versions

  • 26.7.2
  • 26.6.3
  • 2.21.5
  • 3.33.3.1
  • 26.7.0
  • 1.1

Fixed versions or updates

  • No fixed version is stated in this record.

Recommended action

Review the official publisher document before deployment.

Related vulnerabilities

BlackTree CVE Intelligence

Official publisher evidence