[1.5.6]
Update keycloak to 26.5.6
Full Changelog
CVE-2026-1180 - Blind Server-Side Request Forgery (SSRF) in Keycloak OIDC Dynamic Client Registration via jwks_uri oidc
CVE-2026-1035 - Keycloak Refresh Token Reuse Bypass via TOCTOU Race Condition oidc
CVE-2025-14777 - Keycloak IDOR in realm client creating/deleting
CVE-2025-14082 keycloak-server: Keycloak Admin REST API: Improper Access Control leads to sensitive role metadata information disclosure
CVE-2026-3121 - Keycloak: Privilege escalation via manage-clients permission
CVE-2026-3190 - Information Disclosure via improper role enforcement in UMA 2.0 Protection API core
CVE-2026-3911 Keycloak: Information disclosure of disabled user attributes via administrative endpoint user-profile
CVE-2026-2366 Authorization Bypass: Unprivileged tokens can enumerate user organization memberships organizations
Federated user disabled when external DB unavailable, never re-enabled storage
AUTH_SESSION_ID cookie reuse causes cross-user session contamination on re-authentication authentication