Keycloak 26.7.1

26.7.1
Fixed 4
  • WebAuthn authenticator attachment policy is bypassed when the client omits the attachment field
  • New Password is committed when multiple Password Reset is detected
  • 500 error when client requests organization scope with it already set to Default
  • IllegalFormatConversionException in LiquibaseDBLockProviderFactory and wrong time conversion
Security 5
  • JWE request object bypasses requestObjectSignatureAlg enforcement
  • Privilege escalation via hardcoded role mapper injection in manage-clients
  • Keycloak Admin UI Extension brute-force-user User Disclosure via search=id: under FGAP v2
  • Fine-Grained Admin Permissions Bypass in Client Scope Assignment
  • FGAP v2 parent group children endpoint bypasses per-child view permission filter
View original

Upgraded? How did it go?

Discussion