Keycloak 26.6.2

26.6.2
Changed 1
  • Upgrade to Quarkus 3.33.1.1
Fixed 3
  • Allow duplicate user attribute values to be removed
  • Account UI no longer reports error when opening an unknown path
  • Realm import with --import-realm no longer fails with ModelValidationException when Admin Permissions is enabled
Security 16
  • Fix HTTP/2 CONTINUATION Frame Flood Denial of Service (CVE-2026-33871)
  • Fix RFC violation HTTP Request Smuggling primitive via Chunked Extension Quoted-String Parsing (CVE-2026-33870)
  • Fix improper access control on Keycloak Server through UMA resource management endpoints via PUT parameters (CVE-2026-4628)
  • Fix stored XSS in select-organization.ftl with insufficient FreeMarker HTML-escape in inline JS handler (CVE-2026-4048)
  • Fix use of broken or risky cryptographic algorithm vulnerability in bcpkix modules (CVE-2026-5588)
  • Fix acceptable AAGUID policy bypass via packed self-attestation in WebAuthn registration (CVE-2026-6856)
View original

Upgraded? How did it go?

Discussion