Security News

Cybersecurity news aggregator

🔓
HIGH Vulnerabilities Red Hat Errata

RHSA-2026:50848: Important: Red Hat build of Keycloak 26.6.5 Security Update

This security update for Red Hat build of Keycloak 26.6.5 addresses multiple important vulnerabilities, including authorization bypasses in admin and FGAPv2 endpoints, privilege escalation via DCR protocol, and denial-of-service vectors via crafted HTTP/gRPC requests. The advisory includes fixes for CVE-2026-11986 (CVSS 4.9), CVE-2026-14209 (CVSS 4.3), and CVE-2026-14614 (CVSS 5.4), among others. Administrators must upgrade to version 26.6.5 and should perform a full backup before applying the update.
Read Full Article →

Red Hat Product Errata RHSA-2026:50848 - Security Advisory Issued: 2026-08-05 Updated: 2026-08-05 RHSA-2026:50848 - Security Advisory Overview Synopsis Important: Red Hat build of Keycloak 26.6.5 Security Update Type/Severity Security Advisory: Important Topic New Red Hat build of Keycloak 26.6.5 packages are available from the Customer Portal Description Red Hat build of Keycloak 26.6.5 is a standalone server, based on the Keycloak project, that provides authentication and standards-based single sign-on capabilities for web and mobile applications. Security fixes: Authorization Bypass vulnerability in the admin-ui-ext bulk role-mapping-delete endpoints of Keycloak (CVE-2026-11986) Admin UI extension brute-force-user endpoint bypasses FGAPv2 user view restrictions (CVE-2026-14209) FGAP v2 client scope assignment bypass via ClientResource (CVE-2026-14614) FGAP v2 parent group children endpoint bypasses per-child view permission filter (CVE-2026-14615) DCR protocol mapper type-swap policy bypass allows privilege escalation (CVE-2026-15572) Authorization bypass via unnormalized URI matching in PathMatcher (CVE-2026-15573) LDAP entry-DN user search bypasses configured users DN boundary (CVE-2026-16071) Unbounded metric cardinality in user event metrics via request-controlled error text (CVE-2026-16100) Default DCR policy allows role forgery via User Property mappers (CVE-2026-16102) Quarkus REST - Unbounded multipart MIME part-header accumulation allows remote OOM denial of service (CVE-2026-16308) SAML IdP-initiated broker login bypasses link-only restriction (CVE-2026-16442) SAML broker metadata import disables response signature validation (CVE-2026-16443) Denial of Service via specially crafted gRPC requests (CVE-2026-40983) Denial of Service via specially crafted HTTP requests (CVE-2026-40984) Arbitrary code execution via PolymorphicTypeValidator bypass (CVE-2026-54512) Security bypass allows arbitrary code execution (CVE-2026-54513) HTTP Parameter Pollution in OIDC redirect URI allows response parameter duplication - #GHI-604 (CVE-2026-9689) Security policy bypass in JWE-encrypted request object processing (CVE-2026-9793) Brute-force protection bypass in CIBA flow (CVE-2026-9798) Solution Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. Affected Products Red Hat build of Keycloak Text-only Advisories x86_64 Fixes (none) CVEs CVE-2026-9689 CVE-2026-9793 CVE-2026-9798 CVE-2026-11986 CVE-2026-14209 CVE-2026-14614 CVE-2026-14615 CVE-2026-15572 CVE-2026-15573 CVE-2026-16071 CVE-2026-16100 CVE-2026-16102 CVE-2026-16308 CVE-2026-16442 CVE-2026-16443 CVE-2026-40983 CVE-2026-40984 CVE-2026-54512 CVE-2026-54513 References https://access.redhat.com/security/updates/classification/#important The Red Hat security contact is secalert@redhat.com . More contact details at https://access.redhat.com/security/team/contact/ .

Share this article