26.7.3
Checked 5 Oct 2026. BlackTree preserves the last verified facts if a later source check is temporarily unavailable.
Open the official publisher sourcePUBLISHER UPDATE · KEYCLOAK-26.7.3
26.7.3
Scope: Keycloak. This update record adds version, fix and known-issue context. Its publication date is not a lifecycle boundary.
Upgrading Before upgrading refer to the migration guide for a complete list of changes. All resolved issues Security fixes #50785 CVE-2026-35563 : LDAP client implementation in version 2.1.7 does not verify if the server certificate matches the intended LDAP hostname ldap #50997 [ CVE-2026-16093 ] Required signed-JWT assertion policy can be bypassed with unsigned assertion headers oidc #50998 [ CVE-2026-16072 ] Organization managers can create managed members through stored registration links without manage-users organizations #51001 [ CVE-2026-16108 ] Realm default-group reads disclose hidden groups under FGAP v2 admin/fine-grained-permissions #51002 [ CVE-2026-16105 ] Missing per-role authorization on RoleContainerResource composite endpoints admin/rbac #51003 [ CVE-2026-16089 ] Authorization codes can be retargeted to another client session oidc #51005 [ CVE-2026-16104 ] Authenticator config surfaces expose raw reCAPTCHA secrets admin/fine-grained-permissions #51112 [ CVE-2026-16106 ] Incorrect authorization in admin role-composite deletion allows delegated admin to remove privileged child roles admin/fine-grained-permissions #51142 [ CVE-2026-17059 ] Information disclosure: GET /roles/{role}/users returns user PII without the per-user view filter admin/fine-grained-permissions #51279 [ CVE-2026-18218 ] Client not-before revocation is ignored when realm not-before is older but nonzero oidc #51282 [ CVE-2026-18215 ] Microsoft external access-token exchange bypasses configured tenant token-exchange #51283 [ CVE-2026-18201 ] Generic identity-provider creation can bind brokers to organizations without manage-organizations organizations #51286 [ CVE-2026-18209 ] Incomplete fix for redirect_uri OIDC response-parameter injection: forbidden-parameter check (commit 18832bc ) inspects only the query string, not the URL fragment oidc #51287 [ CVE-2026-18214 ] Google external access-token exchange bypasses hosted-domain restriction token-exchange #51378 [ CVE-2026-18571 ] FGAP V2: Group assignment bypass during user creation (POST /users) allows adding unpermitted groups admin/fine-grained-permissions #51379 [ CVE-2026-18572 ] UMA claim token can override the authorization time-policy clock authorization-services #51380 [ CVE-2026-18573 ] Client access-type condition evaluates updates against the old client type oidc #51382 [ CVE-2026-18570 ] Full-scope-disabled client policy validation can be bypassed by omitting fullScopeAllowed oidc #51745 [ CVE-2026-19729 ] Incomplete fix for CVE-2026-9083 — relative path traversal still enables filesystem probing in 26.6.4 core #52028 [ CVE-2026-79652 ] Keycloak jwt-bearer authorization grant does not enforce consentRequired oidc Weaknesses #50581 Admin API: User/group role-mapping endpoints disclose hidden client role metadata under FGAP v2 admin/fine-grained-permissions #50583 Admin API: Composite role endpoints do not filter child roles by FGAP v2 view permission admin/fine-grained-permissions #50990 Admin UI extension effective-role endpoints disclose hidden composite roles admin/fine-grained-permissions #51143 Aggregate policy partial evaluation diverges from runtime semantics under FGAP v2 admin/fine-grained-permissions #51144 Partial evaluation misses ancestor group policies with extendChildren admin/fine-grained-permissions #51202 Client-protocol condition can be bypassed on admin client creation by omitting protocol oidc Bugs #50825 Creating an organization without a domain leads to an error organizations #50963 V1 token-exchange strips the DPoP sender-constraint from a bound access token token-exchange #51510 SQLGrammarException: The incoming request has too many parameters core #51523 Sustained high CPU on all nodes after upgrade admin/api #51554 Admin API per-request cost grows super-linearly with realm count since 26.7.1 admin/api #51589 NPE in RoleUtils.expandCompositeRoles when a cached client scope references a deleted role core #51602 Invalid redirect on https://access.redhat.com/
Not stated. The verified publisher record does not contain a known-issues statement.
Review the official publisher document before deployment.
Checked 5 Oct 2026. BlackTree preserves the last verified facts if a later source check is temporarily unavailable.
Open the official publisher source