RHSA-2026:50848: Important: Red Hat build of Keycloak 26.6.5 Security Update

Published Aug 5, 2026
·
Updated

Important: Red Hat build of Keycloak 26.6.5 Security Update

Other sources

Red Hat build of Keycloak 26.6.5 is a standalone server, based onthe Keycloak project, that provides authentication andstandards-based single sign-on capabilities for web and mobileapplications.Security fixes: Authorization Bypass vulnerability in the admin-ui-ext bulk role-mapping-delete endpoints of Keycloak (CVE-2026-11986) Admin UI extension brute-force-user endpoint bypasses FGAPv2 user view restrictions (CVE-2026-14209) FGAP v2 client scope assignment bypass via ClientResource (CVE-2026-14614) FGAP v2 parent group children endpoint bypasses per-child view permission filter (CVE-2026-14615) DCR protocol mapper type-swap policy bypass allows privilege escalation (CVE-2026-15572) Authorization bypass via unnormalized URI matching in PathMatcher (CVE-2026-15573) LDAP entry-DN user search bypasses configured users DN boundary (CVE-2026-16071) Unbounded metric cardinality in user event metrics via request-controlled error text (CVE-2026-16100) Default DCR policy allows role forgery via User Property mappers (CVE-2026-16102) Quarkus REST - Unbounded multipart MIME part-header accumulation allows remote OOM denial of service (CVE-2026-16308) SAML IdP-initiated broker login bypasses link-only restriction (CVE-2026-16442) SAML broker metadata import disables response signature validation (CVE-2026-16443) Denial of Service via specially crafted gRPC requests (CVE-2026-40983) Denial of Service via specially crafted HTTP requests (CVE-2026-40984) Arbitrary code execution via PolymorphicTypeValidator bypass (CVE-2026-54512) Security bypass allows arbitrary code execution (CVE-2026-54513) HTTP Parameter Pollution in OIDC redirect URI allows response parameter duplication - #GHI-604 (CVE-2026-9689) Security policy bypass in JWE-encrypted request object processing (CVE-2026-9793) Brute-force protection bypass in CIBA flow (CVE-2026-9798)

Red Hat

Affected Software

2 affected components
Red Hat Keycloak=26.6.5
Red Hat Red Hat build of Keycloak

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade redhat/keycloak (Red Hat build of Keycloak) to a version that resolves this vulnerability.

    Fixed in 26.6.5
  2. Operational

    Back up the existing Red Hat build of Keycloak installation before applying the security update, including all applications, configuration files, databases, and database settings.

Event History

Aug 5, 2026
Advisory Published
via Red Hat·12:00 AM
Data Sourced
via Red Hat·12:00 AM
RemedyDescriptionAffected Software
Advisory Published
via Red Hat·04:15 PM
Data Sourced
via Red Hat·04:15 PM
Severity
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of RHSA-2026:50848?

The severity of RHSA-2026:50848 is rated as important.

2

What vulnerability does RHSA-2026:50848 address?

RHSA-2026:50848 addresses an authorization bypass vulnerability in the admin-ui-ext bulk role-mapping-delete endpoints.

3

How do I fix RHSA-2026:50848?

To fix RHSA-2026:50848, you need to update to Red Hat build of Keycloak version 26.6.5 or later.

4

Who is affected by RHSA-2026:50848?

Organizations using Red Hat Keycloak versions prior to 26.6.5 are affected by RHSA-2026:50848.

5

When was RHSA-2026:50848 published?

RHSA-2026:50848 was published on August 5, 2026.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203