26.7.1
Upgrading
Before upgrading refer to the migration guide for a complete list of changes.
All resolved issues
Security fixes
- #49429 [CVE-2026-9793] JWE request object bypasses requestObjectSignatureAlg enforcement
oidc - #50445 [CVE-2026-4629] Privilege escalation via hardcoded role mapper injection in manage-clients
admin/api - #50569 [CVE-2026-14209] Keycloak Admin UI Extension `brute-force-user` User Disclosure via `search=id:` under FGAP v2
admin/fine-grained-permissions - #50615 [CVE-2026-14614] Keycloak 26.6.3 Fine-Grained Admin Permissions Bypass in Client Scope Assignment
admin/fine-grained-permissions - #50617 [CVE-2026-14615] FGAP v2 parent group children endpoint bypasses per-child view permission filter
admin/fine-grained-permissions - #51467 CVE-2026-15573 Authorization bypass via unnormalized uri matching in pathmatcher
- #51468 CVE-2026-15572 DCR protocol mapper type-swap policy bypass allows privilege escalation
- #51469 CVE-2026-16100 Unbounded metric cardinality in user event metrics via request-controlled error text
- #51470 CVE-2026-16442 SAML idp-initiated broker login bypasses link-only restriction
- #51471 CVE-2026-16443 SAML broker metadata import disables response signature validation
- #51472 CVE-2026-16071 LDAP entry-dn user search bypasses configured users dn boundary
- #51473 CVE-2026-16102 Default DCR policy allows role forgery via user property mappers
Bugs
- #50719 WebAuthn authenticator attachment policy is bypassed when the client omits the attachment field
authentication/webauthn - #50750 Clustering test broken in 26.7 release branch
ci - #50836 Kustomize cluster-wide faulty Role&RoleBinding
operator - #50850 New Password is commited when multiple Password Reset is detected
authentication - #50882 500 when client requests `organization` scope with it already set to `Default`
authentication - #50928 IllegalFormatConversionException in LiquibaseDBLockProviderFactory and wrong time conversion
core