26.7.2
Checked 5 Oct 2026. BlackTree preserves the last verified facts if a later source check is temporarily unavailable.
Open the official publisher sourcePUBLISHER UPDATE · KEYCLOAK-26.7.2
26.7.2
Scope: Keycloak. This update record adds version, fix and known-issue context. Its publication date is not a lifecycle boundary.
Upgrading Before upgrading refer to the migration guide for a complete list of changes. All resolved issues Security fixes #49570 CVE-2026-45292 OpenTelemetry Java SDK has Unbounded Memory Allocation in W3C Baggage Propagation dependencies #50616 [ CVE-2026-14613 ] Keycloak 26.6.3 Fine-Grained Admin Permissions Bypass via Role Groups Endpoint admin/fine-grained-permissions #50955 [ CVE-2026-59888 and CVE-2026-59889 ] Upgrade jackson-databind to 2.21.5 to fix #50966 [ CVE-2026-15945 ] Group hierarchy search discloses hidden parent groups under FGAP v2 admin/fine-grained-permissions #51145 [ CVE-2026-17048 ] Keycloak Admin REST API Leaks Vault-Resolved Rotated Client Secrets oidc #51832 CVE-2026-15571 Predictable account-linking hash enables account takeover via malicious oidc client #51833 CVE-2026-18963 Unauthenticated account takeover via reset-credentials flow bypass Weaknesses #50844 show-config prints the vault keystore password in cleartext dist/quarkus Enhancements #51344 Upgrade to Quarkus 3.33.3.1 Bugs #50751 Password denylist: false fpp warning on startup with large pre-computed .bloom file authentication #50849 Correct SCIM name.formated scim #50855 Rotated client secret remains valid when the feature is disabled oidc #51054 Invalid redirect URI on logout from pages with sub-tab hash fragments admin/ui #51061 Parameterized UserPropertyMapper exposes target user attributes without permission check core #51087 Passkey icons use wrong color variant when realm disables dark mode authentication/webauthn #51088 Verify email not working in incognito browser tab after Keycloak restart authentication #51131 Warning "Proactive closing of the session was missed - refinements are needed to TransactionSessionHandler related logic" appears core #51154 Upgrade to 26.7.0 fails with preview features as the stateless cluster provider captures a null NodeInfo before postInit infinispan #51164 WebAuthn tests are being skipped in Github workflows workflows #51182 Large HTTP/2 request headers are rejected with a bare 500 and no log; same request works over HTTP/1.1 dist/quarkus #51323 Custom realm-level role named admin cannot be updated in non-master realms after Keycloak 26.7.0 admin/rbac #51331 Adding org member fails with 500 with stateless:v1 feature enabled organizations #51407 The dist for Java API docs is empty docs #51449 Incorrect query parameter name for "max" #51476 Invalid link for https://www.ietf.org/rfc/rfc4559.txt docs
Not stated. The verified publisher record does not contain a known-issues statement.
Review the official publisher document before deployment.
Checked 5 Oct 2026. BlackTree preserves the last verified facts if a later source check is temporarily unavailable.
Open the official publisher source