- Fixed several SAML broker security vulnerabilities (CVE‑2026‑3047, CVE‑2026‑3009, CVE‑2026‑2603, CVE‑2026‑2092) that allowed authentication bypass and improper IdP handling.
- Refer to the migration guide before upgrading to version 26.5.5.
Official Keycloak changelog summary with source attribution, release tags, and community reactions.
Track this Keycloak release note alongside related changelog updates, risky changes, and weekly digest signals from the developer community.
Every summary should remain traceable to the original changelog or release source.
Turn this Keycloak release note into a weekly digest for the tools you actually use.
Create digestPatched multiple critical CVEs (OpenTelemetry memory allocation, admin permission bypass, Jackson upgrade, group hierarchy disclosure, vault secret leak, account linking hash, reset credentials bypass) and fixed a config leak of the vaul...
Security patches address CVE‑2026‑9793 (JWE request object enforcement), CVE‑2026‑4629 (hard‑coded role mapper injection), CVE‑2026‑14209 (admin UI brute‑force), and two fine‑grained admin permission bypasses (client scope and group chil...