- What: Red Hat released security update for Keycloak images
- Impact: Includes security fixes for Keycloak 26.4.14
Red Hat Product Errata RHSA-2026:50847 - Security Advisory Issued: 2026-08-05 Updated: 2026-08-05 RHSA-2026:50847 - Security Advisory Overview Updated Images Synopsis Important: Red Hat build of Keycloak 26.4.14 Images Security Update Type/Severity Security Advisory: Important Topic New images are available for Red Hat build of Keycloak 26.4.14 and Red Hat build of Keycloak 26.4.14 Operator, running on OpenShift Container Platform Description Red Hat build of Keycloak is an integrated sign-on solution, available as a Red Hat JBoss Middleware for OpenShift containerized image. The Red Hat build of Keycloak for OpenShift image provides an authentication server that you can use to log in centrally, log out, and register. You can also manage user accounts for web applications, mobile applications, and RESTful web services. Red Hat build of Keycloak Operator for OpenShift simplifies deployment and management of Keycloak 26.4.14 clusters. This erratum releases new images for Red Hat build of Keycloak 26.4.14 for use within the OpenShift Container Platform cloud computing Platform-as-a-Service (PaaS) for on-premise or private cloud deployments, aligning with the standalone product release. Security fixes: Admin UI extension brute-force-user endpoint bypasses FGAPv2 user view restrictions (CVE-2026-14209) FGAP v2 client scope assignment bypass via ClientResource (CVE-2026-14614) FGAP v2 parent group children endpoint bypasses per-child view permission filter (CVE-2026-14615) DCR protocol mapper type-swap policy bypass allows privilege escalation (CVE-2026-15572) Authorization bypass via unnormalized URI matching in PathMatcher (CVE-2026-15573) LDAP entry-DN user search bypasses configured users DN boundary (CVE-2026-16071) Default DCR policy allows role forgery via User Property mappers (CVE-2026-16102) Quarkus REST - Unbounded multipart MIME part-header accumulation allows remote OOM denial of service (CVE-2026-16308) SAML IdP-initiated broker login bypasses link-only restriction (CVE-2026-16442) SAML broker metadata import disables response signature validation (CVE-2026-16443) Privilege escalation through hardcoded role mapper injection (CVE-2026-4629) Arbitrary code execution via PolymorphicTypeValidator bypass (CVE-2026-54512) Security bypass allows arbitrary code execution (CVE-2026-54513) HTTP Parameter Pollution in OIDC redirect URI allows response parameter duplication - #GHI-604 (CVE-2026-9689) Security policy bypass in JWE-encrypted request object processing (CVE-2026-9793) Brute-force protection bypass in CIBA flow (CVE-2026-9798) Authorization bypass via incorrect URI comparison (CVE-2026-9800) Brute-force protection bypass in CIBA flow (CVE-2026-9798) Solution Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. Affected Products Red Hat build of Keycloak Text-only Advisories x86_64 Fixes (none) CVEs CVE-2025-5278 CVE-2025-13151 CVE-2026-4629 CVE-2026-5435 CVE-2026-5928 CVE-2026-6238 CVE-2026-9689 CVE-2026-9793 CVE-2026-9798 CVE-2026-9800 CVE-2026-14209 CVE-2026-14614 CVE-2026-14615 CVE-2026-15572 CVE-2026-15573 CVE-2026-16071 CVE-2026-16102 CVE-2026-16308 CVE-2026-16442 CVE-2026-16443 CVE-2026-41254 CVE-2026-46917 CVE-2026-46968 CVE-2026-47010 CVE-2026-47021 CVE-2026-47027 CVE-2026-47059 CVE-2026-47063 CVE-2026-54369 CVE-2026-54370 CVE-2026-54512 CVE-2026-54513 CVE-2026-60147 References https://access.redhat.com/security/updates/classification/#important aarch64 rhbk/keycloak-rhel9@sha256:cc475d34ac199de0908a32efa630c219469076feb74fd970d617c40cc90911f8 rhbk/keycloak-rhel9-operator@sha256:0d3ea94f75c1b4528722db2c216ff2267ec17ba16adf3f703afb82354f0fdc68 ppc64le rhbk/keycloak-rhel9@sha256:130dfc422476647b5098a317a38964e7ea6a2a3f1a63d91f91dfb993921b356b rhbk/keycloak-rhel9-operator@sha256:399c59b8e63de5b6aa4e64008644550b98feb0957214e58dc7c6a5246dde3c87 s390x rhbk/keycloak-rhel9@sha256:8a6fd6c12811ce179fc1248c63a152d173c12866b84f8b8364f4f3ed42b7ba58 rhbk/keycloak-rhel9-operator@sha256:f9f35a75d3029edf5ff82351c0b60ad0dd8672c3fa8f22f672954c248f9e0c63 x86_64 rhbk/keycloak-operator-bundle@sha256:2c25b3107aee4f1fc25530f099fa683ba3077c185d581e7caa777c4410383085 rhbk/keycloak-rhel9@sha256:fc0390f65497ad6274f3db55ac796eb792255a8780578ab4d98aec9f42c23bc0 rhbk/keycloak-rhel9-operator@sha256:330350e0cd77afca88886156c2668ae4bca75865e90362cbcf9657197bfa21e8 The Red Hat security contact is secalert@redhat.com . More contact details at https://access.redhat.com/security/team/contact/ .