Red Hat build of Keycloak
Red Hat build of Keycloak is a cloud-native Identity Access Management solution based on the popular open source Keycloak project. Red Hat build of Keycloak replaces any planned future releases of Red Hat Single Sign-On. You can migrate Red Hat Single Sign-On to Red Hat build of Keycloak now.
browse_doc
Release NotesRelease Notes
Red Hat build of Keycloak Supported ConfigurationsSupported Configurations and Component Details
Getting Started GuideInstalling Red Hat build of Keycloak
Upgrading GuideUpgrading Red Hat build of Keycloak
Server Configuration GuideManaging the Red Hat build of Keycloak Server
Securing Applications and Services GuideUsing Red Hat build of Keycloak
latest_security
| severity | advisory_cve | synopsis | date |
|---|---|---|---|
| severity Important | advisory_cve(RHSA-2026:50849) Important: Red Hat build of Keycloak 26.6.5 Images Security Update | synopsis Important: Red Hat build of Keycloak 26.6.5 Images Security Update | date |
| severity Important | advisory_cve(RHSA-2026:50848) Important: Red Hat build of Keycloak 26.6.5 Security Update | synopsis Important: Red Hat build of Keycloak 26.6.5 Security Update | date |
| severity Important | advisory_cveCVE-2026-16443 | synopsis A flaw was found in the SAML metadata import functionality of the keycloak-services component, which is the core engine for identity brokering in Red Hat Build of Keycloak. When importing identity provider metadata that lacks specific usage attributes for keys, the system incorrectly disables signature validation for SAML responses even if a signing certificate is provided. This issue allows an unauthenticated attacker to forge a SAML response and gain unauthorized access to a user account by knowing their external identifier. | date |
| severity Important | advisory_cveCVE-2026-16442 | synopsis A flaw was found in the SAML broker component of Keycloak, which is used to manage identity federation and user authentication. The issue occurs because the IdP-initiated Single Sign-On endpoint fails to check if a provider is restricted to account linking only. This allows an attacker with control over a linked upstream identity to bypass login restrictions and gain full access to a local user account. | date |
| severity Moderate | advisory_cveCVE-2026-14615 | synopsis A flaw was found in the Fine-Grained Admin Permissions (FGAP) v2 implementation within Keycloak's administrative services. When FGAP v2 is enabled, the system fails to properly filter child groups based on the caller's specific permissions when requested through a parent group. This allows a delegated administrator to view details of child groups they are not authorized to access directly, including group names, paths, and custom attributes. | date |
top_resources
Knowledgebase
Access articles and solutions to find answers to your questions.
Troubleshooting
Connect to the right information to self-solve issues quickly and efficiently.
Supported configurations
Red Hat provides both production and development support for supported configurations and tested integrations.
Component details
Component details for each release of Red Hat build of Keycloak.