# Keycloak 26.7.2 - Product: Keycloak (https://whatsnew.fyi/product/keycloak) - Vendor: Red Hat - Date: 2026-08-19 - Version: 26.7.2 - Original notes: https://github.com/keycloak/keycloak/releases/tag/26.7.2 - Permalink: https://whatsnew.fyi/product/keycloak/releases/26.7.2 What's New is an index, not a publisher: every entry below links to the vendor's own release notes, which are the authoritative source. Entries are labelled where they are hand-curated sample data, pre-releases, or drawn from a secondary source such as a developer blog. Reuse: the summaries, labels and curation here are © What's New. Quote freely with attribution and a link back; wholesale republication of the corpus is not permitted — terms: https://whatsnew.fyi/terms. The vendors' own release notes remain their publishers'. --- - **security** — Fixed CVE-2026-45292 OpenTelemetry Java SDK unbounded memory allocation in W3C Baggage Propagation - **security** — Fixed CVE-2026-14613 fine-grained admin permissions bypass via role groups endpoint - **security** — Fixed CVE-2026-59888 and CVE-2026-59889 by upgrading jackson-databind to 2.21.5 - **security** — Fixed CVE-2026-15945 group hierarchy search disclosure of hidden parent groups under fine-grained admin permissions v2 - **security** — Fixed CVE-2026-17048 admin REST API leaking vault-resolved rotated client secrets - **security** — Fixed CVE-2026-15571 predictable account-linking hash enabling account takeover via malicious OIDC client - **security** — Fixed CVE-2026-18963 unauthenticated account takeover via reset-credentials flow bypass - **security** — Fixed show-config command printing vault keystore password in cleartext - **changed** — Upgrade to Quarkus 3.33.3.1 - **fixed** — Fixed password denylist false positive warning on startup with large pre-computed bloom file - **fixed** — Corrected SCIM name.formated field - **fixed** — Fixed rotated client secret remaining valid when the feature is disabled - **fixed** — Fixed invalid redirect URI on logout from pages with sub-tab hash fragments - **fixed** — Fixed parameterized UserPropertyMapper exposing target user attributes without permission check - **fixed** — Fixed passkey icons using wrong color variant when realm disables dark mode - **fixed** — Fixed verify email not working in incognito browser tab after Keycloak restart - **fixed** — Fixed warning about proactive closing of session being missed in TransactionSessionHandler logic - **fixed** — Fixed upgrade to 26.7.0 failing with preview features when stateless cluster provider captures null NodeInfo before postInit - **fixed** — Fixed custom realm-level role named admin not being updatable in non-master realms after Keycloak 26.7.0 - **fixed** — Fixed adding org member failing with 500 error when stateless:v1 feature is enabled

Upgrading

Before upgrading refer to the migration guide for a complete list of changes.

All resolved issues

Security fixes

Weaknesses

Enhancements

Bugs