26.7.1
Fixed 4
- WebAuthn authenticator attachment policy is bypassed when the client omits the attachment field
- New Password is committed when multiple Password Reset is detected
- 500 error when client requests organization scope with it already set to Default
- IllegalFormatConversionException in LiquibaseDBLockProviderFactory and wrong time conversion
Security 5
- JWE request object bypasses requestObjectSignatureAlg enforcement
- Privilege escalation via hardcoded role mapper injection in manage-clients
- Keycloak Admin UI Extension brute-force-user User Disclosure via search=id: under FGAP v2
- Fine-Grained Admin Permissions Bypass in Client Scope Assignment
- FGAP v2 parent group children endpoint bypasses per-child view permission filter