- Issued:
- 2026-09-16
- Updated:
- 2026-09-16
RHSA-2026:68278 - Security Advisory
Synopsis
Important: Red Hat build of Keycloak 26.6.7 Security Update
Type/Severity
Security Advisory: Important
Topic
New Red Hat build of Keycloak 26.6.7 packages are available from the Customer Portal
Description
Red Hat build of Keycloak 26.6.7 is a standalone server, based on
the Keycloak project, that provides authentication and
standards-based single sign-on capabilities for web and mobile
applications.
Security fixes:
- Group hierarchy search discloses hidden parent groups under FGAP v2 (CVE-2026-15945)
- Organization invitation link exposure allows unauthorized member creation (CVE-2026-16072)
- Authorization codes can be retargeted to another client session (CVE-2026-16089)
- Required signed-JWT assertion policy can be bypassed with unsigned assertion headers (CVE-2026-16093)
- Authenticator config endpoint exposes raw reCAPTCHA secrets to view-only admins (CVE-2026-16104)
- Missing per-role authorization on RoleContainerResource composite endpoints (CVE-2026-16105)
- Incorrect authorization in admin role-composite deletion allows delegated admin to remove privileged child roles (CVE-2026-16106)
- Realm default-group reads disclose hidden groups under FGAP v2 (CVE-2026-16108)
- Information disclosure via role-users endpoint bypasses per-user view filter (CVE-2026-17059)
- Privilege escalation via impersonation role allows takeover of realm administrator accounts (CVE-2026-17526)
- RESTeasy SourceProvider remote unauthenticated file read (CVE-2026-17615)
- Generic identity-provider creation can bind brokers to organizations without manage-organizations (CVE-2026-18201)
- OIDC redirect_uri fragment bypass in HTTP parameter pollution check (CVE-2026-18209)
- SAML Redirect DEFLATE helpers leak native zlib state (CVE-2026-18212)
- Google external access-token exchange bypasses hosted-domain restriction (CVE-2026-18214)
- Microsoft external access-token exchange bypasses configured tenant (CVE-2026-18215)
- Client not-before revocation ignored when realm not-before is older but nonzero (CVE-2026-18218)
- Full-scope-disabled client policy validation bypass via omitted fullScopeAllowed (CVE-2026-18570)
- FGAP V2 group assignment bypass during user creation (CVE-2026-18571)
- UMA claim token can override authorization time-policy evaluation attributes (CVE-2026-18572)
- Client access-type policy condition bypass during client update (CVE-2026-18573)
- Broker-originated username collision causes account lockout (CVE-2026-19607)
- Incomplete fix for arbitrary filesystem path probing via keystore parameters (CVE-2026-19729)
- Remote Code Execution via prototype pollution in Framework Mode (CVE-2026-42211)
- TLS hostname verification bypass via OpenSSL client path misconfiguration (CVE-2026-62243)
- Incomplete fix for CVE-2026-15573 allows policy enforcer bypass via percent-encoded URI segments (CVE-2026-74909)
- unauthenticated DoS via unbounded locale caching (CVE-2026-79651)
- JWT Bearer authorization grant does not enforce consentRequired (CVE-2026-79652)
Solution
Before applying the update, back up your existing installation,
including all applications, configuration files, databases and
database settings, and so on.
Affected Products
- Red Hat build of Keycloak Text-only Advisories x86_64
Fixes
(none)CVEs
- CVE-2026-15945
- CVE-2026-16072
- CVE-2026-16089
- CVE-2026-16093
- CVE-2026-16104
- CVE-2026-16105
- CVE-2026-16106
- CVE-2026-16108
- CVE-2026-17059
- CVE-2026-17526
- CVE-2026-17615
- CVE-2026-18201
- CVE-2026-18209
- CVE-2026-18212
- CVE-2026-18214
- CVE-2026-18215
- CVE-2026-18218
- CVE-2026-18570
- CVE-2026-18571
- CVE-2026-18572
- CVE-2026-18573
- CVE-2026-19607
- CVE-2026-19729
- CVE-2026-42211
- CVE-2026-62243
- CVE-2026-74909
- CVE-2026-79651
- CVE-2026-79652
The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.