Category

security

Articles about security from the Skycloak team.

security

Keycloak 26.7.4 Security Fixes: A Self-Hosted Patch Checklist

Keycloak 26.7.4 fixes six CVEs, from a SAML memory leak to impersonation of realm admins. Which reach 26.6 and 26.4,…

Guilliano Molaire Guilliano Molaire 10 min read
security

CVE-2026-96448: Keycloak FGAP Composite Privilege Escalation

CVE-2026-96448 is a Keycloak privilege escalation: an FGAP v2 delegated admin assigns a composite role that hides realm-admin. How it…

Guilliano Molaire Guilliano Molaire 12 min read
security

CVE-2026-97176: Keycloak Step-Up Authentication Bypass

CVE-2026-97176 can let Keycloak issue a token at a lower assurance level than a client's essential acr demands, skipping step-up.…

Guilliano Molaire Guilliano Molaire 9 min read
security

CVE-2026-97177: Keycloak Delegated Admin Account Takeover

CVE-2026-97177 enables account takeover in Keycloak: a delegated admin denied reset-password can still set passwords via user update. How it…

Guilliano Molaire Guilliano Molaire 9 min read
security

CVE-2026-97846: Keycloak Token Exchange Drops mTLS Binding

CVE-2026-97846 lets Keycloak standard token exchange issue an unbound Bearer token for an mTLS-bound client. What it breaks, who is…

Guilliano Molaire Guilliano Molaire 11 min read
security

CVE-2026-79651: Keycloak Unauthenticated Locale Cache DoS

CVE-2026-79651 lets anyone exhaust Keycloak heap via a public theme localization endpoint. It is fixed in 26.7.4, 26.6.7 and 26.4.16.…

Guilliano Molaire Guilliano Molaire 10 min read
security

Harden Keycloak with Claude Code and Cursor: An AI-Assisted Security Review Playbook

Use Claude Code or Cursor to review Keycloak realm exports safely: redact secrets, catch PKCE and audience mistakes, and keep…

Guilliano Molaire Guilliano Molaire 4 min read
security

Secure Your App with AI: What AI AppSec Can and Cannot Replace in IAM

AI coding agents find bugs and bad configs. They do not replace token issuance, audience checks, step-up, or revocation. Here…

Guilliano Molaire Guilliano Molaire 4 min read
security

CVE-2026-95503: Keycloak Kerberos Does Not Verify the KDC

CVE-2026-95503 lets an adjacent-network attacker spoof the KDC when Keycloak does Kerberos password authentication without SPNEGO. No fixed release yet.

Guilliano Molaire Guilliano Molaire 10 min read
Keycloak

The US CLOUD Act and Your Keycloak Data: What It Actually Reaches

The CLOUD Act follows the provider, not the datacentre. What that means for Keycloak in the EU, and the questions…

Guilliano Molaire Guilliano Molaire 12 min read

Stay ahead on identity & security

Get tutorials, product updates, and Keycloak tips delivered to your inbox.

© 2026 Skycloak. All Rights Reserved. Design by Yasser Soliman