- Fixed Operator CSV createdAt field format (issue #26427)
- Resolved UI internal server error when updating Refresh Token Max Reuse (issue #26597)
- Fixed realm-level access token lifespan modification crash (issue #26665)
Official Keycloak changelog summary with source attribution, release tags, and community reactions.
Track this Keycloak release note alongside related changelog updates, risky changes, and weekly digest signals from the developer community.
Every summary should remain traceable to the original changelog or release source.
Turn this Keycloak release note into a weekly digest for the tools you actually use.
Create digestPatched multiple critical CVEs (OpenTelemetry memory allocation, admin permission bypass, Jackson upgrade, group hierarchy disclosure, vault secret leak, account linking hash, reset credentials bypass) and fixed a config leak of the vaul...
Security patches address CVE‑2026‑9793 (JWE request object enforcement), CVE‑2026‑4629 (hard‑coded role mapper injection), CVE‑2026‑14209 (admin UI brute‑force), and two fine‑grained admin permission bypasses (client scope and group chil...