Red Hat Product Errata RHSA-2026:50848 - Security Advisory Issued: 2026-08-05 Updated: 2026-08-05 RHSA-2026:50848 - Security Advisory Overview Synopsis Important: Red Hat build of Keycloak 26.6.5 Security Update Type/Severity Security Advisory: Important Topic New Red Hat build of Keycloak 26.6.5 packages are available from the Customer Portal Description Red Hat build of Keycloak 26.6.5 is a standalone server, based on the Keycloak project, that provides authentication and standards-based single sign-on capabilities for web and mobile applications. Security fixes: Authorization Bypass vulnerability in the admin-ui-ext bulk role-mapping-delete endpoints of Keycloak (CVE-2026-11986) Admin UI extension brute-force-user endpoint bypasses FGAPv2 user view restrictions (CVE-2026-14209) FGAP v2 client scope assignment bypass via ClientResource (CVE-2026-14614) FGAP v2 parent group children endpoint bypasses per-child view permission filter (CVE-2026-14615) DCR protocol mapper type-swap policy bypass allows privilege escalation (CVE-2026-15572) Authorization bypass via unnormalized URI matching in PathMatcher (CVE-2026-15573) LDAP entry-DN user search bypasses configured users DN boundary (CVE-2026-16071) Unbounded metric cardinality in user event metrics via request-controlled error text (CVE-2026-16100) Default DCR policy allows role forgery via User Property mappers (CVE-2026-16102) Quarkus REST - Unbounded multipart MIME part-header accumulation allows remote OOM denial of service (CVE-2026-16308) SAML IdP-initiated broker login bypasses link-only restriction (CVE-2026-16442) SAML broker metadata import disables response signature validation (CVE-2026-16443) Denial of Service via specially crafted gRPC requests (CVE-2026-40983) Denial of Service via specially crafted HTTP requests (CVE-2026-40984) Arbitrary code execution via PolymorphicTypeValidator bypass (CVE-2026-54512) Security bypass allows arbitrary code execution (CVE-2026-54513) HTTP Parameter Pollution in OIDC redirect URI allows response parameter duplication - #GHI-604 (CVE-2026-9689) Security policy bypass in JWE-encrypted request object processing (CVE-2026-9793) Brute-force protection bypass in CIBA flow (CVE-2026-9798) Solution Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. Affected Products Red Hat build of Keycloak Text-only Advisories x86_64 Fixes (none) CVEs CVE-2026-9689 CVE-2026-9793 CVE-2026-9798 CVE-2026-11986 CVE-2026-14209 CVE-2026-14614 CVE-2026-14615 CVE-2026-15572 CVE-2026-15573 CVE-2026-16071 CVE-2026-16100 CVE-2026-16102 CVE-2026-16308 CVE-2026-16442 CVE-2026-16443 CVE-2026-40983 CVE-2026-40984 CVE-2026-54512 CVE-2026-54513 References https://access.redhat.com/security/updates/classification/#important The Red Hat security contact is secalert@redhat.com . More contact details at https://access.redhat.com/security/team/contact/ .
This security update for Red Hat build of Keycloak 26.6.5 addresses multiple important vulnerabilities, including authorization bypasses in admin and FGAPv2 endpoints, privilege escalation via DCR protocol, and denial-of-service vectors via crafted HTTP/gRPC requests. The advisory includes fixes for CVE-2026-11986 (CVSS 4.9), CVE-2026-14209 (CVSS 4.3), and CVE-2026-14614 (CVSS 5.4), among others. Administrators must upgrade to version 26.6.5 and should perform a full backup before applying the update.