RHSA-2026:50846: Important: Red Hat build of Keycloak 26.4.14 Security Update
Red Hat build of Keycloak 26.4.14 is a standalone server, based onthe Keycloak project, that provides authentication andstandards-based single sign-on capabilities for web and mobileapplications.Security fixes: Admin UI extension brute-force-user endpoint bypasses FGAPv2 user view restrictions (CVE-2026-14209) FGAP v2 client scope assignment bypass via ClientResource (CVE-2026-14614) FGAP v2 parent group children endpoint bypasses per-child view permission filter (CVE-2026-14615) DCR protocol mapper type-swap policy bypass allows privilege escalation (CVE-2026-15572) Authorization bypass via unnormalized URI matching in PathMatcher (CVE-2026-15573) LDAP entry-DN user search bypasses configured users DN boundary (CVE-2026-16071) Default DCR policy allows role forgery via User Property mappers (CVE-2026-16102) Quarkus REST - Unbounded multipart MIME part-header accumulation allows remote OOM denial of service (CVE-2026-16308) SAML IdP-initiated broker login bypasses link-only restriction (CVE-2026-16442) SAML broker metadata import disables response signature validation (CVE-2026-16443) Privilege escalation through hardcoded role mapper injection (CVE-2026-4629) Arbitrary code execution via PolymorphicTypeValidator bypass (CVE-2026-54512) Security bypass allows arbitrary code execution (CVE-2026-54513) HTTP Parameter Pollution in OIDC redirect URI allows response parameter duplication - #GHI-604 (CVE-2026-9689) Security policy bypass in JWE-encrypted request object processing (CVE-2026-9793) Brute-force protection bypass in CIBA flow (CVE-2026-9798) Authorization bypass via incorrect URI comparison (CVE-2026-9800)
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Red Hat build of Keycloakto a version that resolves this vulnerability.Fixed in 26.4.14 - Operational
Back up your existing Keycloak installation before applying the security update, including all applications, configuration files, databases, and database settings.
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:50846?
The severity of RHSA-2026:50846 is classified as Important.
What vulnerability does RHSA-2026:50846 address?
RHSA-2026:50846 addresses a brute-force-user endpoint bypass in the Admin UI extension.
How do I fix RHSA-2026:50846?
To fix RHSA-2026:50846, you should update to Red Hat build of Keycloak version 26.4.14 or later.
What are the potential impacts of not addressing RHSA-2026:50846?
Not addressing RHSA-2026:50846 could expose your application to unauthorized access due to the brute-force-user endpoint bypass.
Is there a workaround for RHSA-2026:50846 until I can apply the update?
Currently, there are no documented workarounds available for RHSA-2026:50846, so applying the update is recommended.