The Keycloak Team reports:
- [CVE-2026-35563]: LDAP client implementation in version 2.1.7 does not verify if the server certificate matches the intended LDAP hostname
- [CVE-2026-16093]: Required signed-JWT assertion policy can be bypassed with unsigned assertion headers
- [CVE-2026-16072]: Organization managers can create managed members through stored registration links without manage-users
- [CVE-2026-16108]: Realm default-group reads disclose hidden groups under FGAP v2
- [CVE-2026-16105]: Missing per-role authorization on RoleContainerResource composite endpoints
- [CVE-2026-16089]: Authorization codes can be retargeted to another client session
- [CVE-2026-16104]: Authenticator config surfaces expose raw reCAPTCHA secrets
- [CVE-2026-16106]: Incorrect authorization in admin role-composite deletion allows delegated admin to remove privileged child roles
- [CVE-2026-17059]: Information disclosure: GET /roles/{role}/users returns user PII without the per-user view filter
- [CVE-2026-18218]: Client not-before revocation is ignored when realm not-before is older but nonzero
- [CVE-2026-18215]: Microsoft external access-token exchange bypasses configured tenant
- [CVE-2026-18201]: Generic identity-provider creation can bind brokers to organizations without manage-organizations
- [CVE-2026-18209]: Incomplete fix for redirect_uri OIDC response-parameter injection: forbidden-parameter check (commit 18832bca) inspects only the query string, not the URL fragment
- [CVE-2026-18214]: Google external access-token exchange bypasses hosted-domain restriction
- [CVE-2026-18571]: FGAP V2: Group assignment bypass during user creation (POST /users) allows adding unpermitted groups
- [CVE-2026-18572]: UMA claim token can override the authorization time-policy clock
- [CVE-2026-18573]: Client access-type condition evaluates updates against the old client type
- [CVE-2026-18570]: Full-scope-disabled client policy validation can be bypassed by omitting fullScopeAllowed
- [CVE-2026-19729]: Incomplete fix for CVE-2026-9083 — relative path traversal still enables filesystem probing in 26.6.4
- [CVE-2026-79652]: Keycloak jwt-bearer authorization grant does not enforce consentRequired