# Keycloak 26.7.3 - Product: Keycloak (https://whatsnew.fyi/product/keycloak) - Vendor: Red Hat - Date: 2026-08-31 - Version: 26.7.3 - Original notes: https://github.com/keycloak/keycloak/releases/tag/26.7.3 - Permalink: https://whatsnew.fyi/product/keycloak/releases/26.7.3 What's New is an index, not a publisher: every entry below links to the vendor's own release notes, which are the authoritative source. Entries are labelled where they are hand-curated sample data, pre-releases, or drawn from a secondary source such as a developer blog. Reuse: the summaries, labels and curation here are © What's New. Quote freely with attribution and a link back; wholesale republication of the corpus is not permitted — terms: https://whatsnew.fyi/terms. The vendors' own release notes remain their publishers'. --- - **security** — Fix LDAP client implementation certificate hostname verification - **security** — Fix required signed-JWT assertion policy bypass with unsigned assertion headers - **security** — Fix organization managers creating managed members through stored registration links without manage-users permission - **security** — Fix realm default-group reads disclosing hidden groups under FGAP v2 - **security** — Fix missing per-role authorization on RoleContainerResource composite endpoints - **security** — Fix authorization codes being retargeted to another client session - **security** — Fix authenticator config surfaces exposing raw reCAPTCHA secrets - **security** — Fix incorrect authorization in admin role-composite deletion allowing delegated admin to remove privileged child roles - **security** — Fix GET /roles/{role}/users returning user PII without per-user view filter - **security** — Fix client not-before revocation being ignored when realm not-before is older but nonzero - **security** — Fix Microsoft external access-token exchange bypassing configured tenant - **security** — Fix generic identity-provider creation binding brokers to organizations without manage-organizations - **security** — Fix redirect_uri OIDC response-parameter injection by checking URL fragment not only query string - **security** — Fix Google external access-token exchange bypassing hosted-domain restriction - **security** — Fix FGAP V2 group assignment bypass during user creation allowing adding unpermitted groups - **security** — Fix UMA claim token overriding authorization time-policy clock - **security** — Fix client access-type condition evaluating updates against old client type - **security** — Fix full-scope-disabled client policy validation bypass by omitting fullScopeAllowed - **security** — Fix relative path traversal enabling filesystem probing in path handling - **security** — Fix jwt-bearer authorization grant not enforcing consentRequired

Upgrading

Before upgrading refer to the migration guide for a complete list of changes.

All resolved issues

Security fixes