- Issued:
- 2026-09-16
- Updated:
- 2026-09-16
RHSA-2026:68280 - Security Advisory
Synopsis
Important: Red Hat build of Keycloak 26.4.16 Security Update
Type/Severity
Security Advisory: Important
Topic
New Red Hat build of Keycloak 26.4.16 packages are available from the Customer Portal
Description
Red Hat build of Keycloak 26.4.16 is a standalone server, based on
the Keycloak project, that provides authentication and
standards-based single sign-on capabilities for web and mobile
applications.
Security fixes:
- Privilege escalation via impersonation role allows takeover of realm administrator accounts (CVE-2026-17526)
- SAML Redirect DEFLATE helpers leak native zlib state (CVE-2026-18212)
- Broker-originated username collision causes account lockout (CVE-2026-19607)
- Incomplete fix for arbitrary filesystem path probing via keystore parameters (CVE-2026-19729)
- TLS hostname verification bypass via OpenSSL client path misconfiguration (CVE-2026-62243)
- Incomplete fix for CVE-2026-15573 allows policy enforcer bypass via percent-encoded URI segments (CVE-2026-74909)
- unauthenticated DoS via unbounded locale caching (CVE-2026-79651)
Solution
Before applying the update, back up your existing installation,
including all applications, configuration files, databases and
database settings, and so on.
Affected Products
- Red Hat build of Keycloak Text-only Advisories x86_64
Fixes
(none)CVEs
The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.