26.6.2
Changed 1
- Upgrade to Quarkus 3.33.1.1
Fixed 3
- Allow duplicate user attribute values to be removed
- Account UI no longer reports error when opening an unknown path
- Realm import with --import-realm no longer fails with ModelValidationException when Admin Permissions is enabled
Security 16
- Fix HTTP/2 CONTINUATION Frame Flood Denial of Service (CVE-2026-33871)
- Fix RFC violation HTTP Request Smuggling primitive via Chunked Extension Quoted-String Parsing (CVE-2026-33870)
- Fix improper access control on Keycloak Server through UMA resource management endpoints via PUT parameters (CVE-2026-4628)
- Fix stored XSS in select-organization.ftl with insufficient FreeMarker HTML-escape in inline JS handler (CVE-2026-4048)
- Fix use of broken or risky cryptographic algorithm vulnerability in bcpkix modules (CVE-2026-5588)
- Fix acceptable AAGUID policy bypass via packed self-attestation in WebAuthn registration (CVE-2026-6856)
- Fix multiple Bouncy Castle CVEs (CVE-2026-0636, CVE-2026-3505, CVE-2026-5598)
- Fix denial of service when sending a crafted request to the /saml endpoint (CVE-2026-7307)
- Fix redirect URI validation bypass (CVE-2026-7504)
- Fix access token disclosure and implicit flow bypass via forged client data (CVE-2026-7571)
- Fix session fixation in OIDC login flow leading to account takeover (CVE-2026-7507)
- Fix execute-actions token replay allowing unauthorized WebAuthn credential enrollment on victim account (CVE-2026-37982)
- Fix OIDC introspection endpoint not enforcing audience restriction, leaking claims from lightweight access tokens (CVE-2026-37979)
- Fix cross-role PII leakage via evaluate-scopes endpoints bypassing user view permission (CVE-2026-37978)
- Fix Keycloak Authorization Services Protection API IDOR (CVE-2026-4630)
- Fix broken access control in Account Resources User Lookup allowing PII enumeration (CVE-2026-37981)