Articles about security from the Skycloak team.
Keycloak 26.7.4 fixes six CVEs, from a SAML memory leak to impersonation of realm admins. Which reach 26.6 and 26.4,…
CVE-2026-96448 is a Keycloak privilege escalation: an FGAP v2 delegated admin assigns a composite role that hides realm-admin. How it…
CVE-2026-97176 can let Keycloak issue a token at a lower assurance level than a client's essential acr demands, skipping step-up.…
CVE-2026-97177 enables account takeover in Keycloak: a delegated admin denied reset-password can still set passwords via user update. How it…
CVE-2026-97846 lets Keycloak standard token exchange issue an unbound Bearer token for an mTLS-bound client. What it breaks, who is…
CVE-2026-79651 lets anyone exhaust Keycloak heap via a public theme localization endpoint. It is fixed in 26.7.4, 26.6.7 and 26.4.16.…
Use Claude Code or Cursor to review Keycloak realm exports safely: redact secrets, catch PKCE and audience mistakes, and keep…
AI coding agents find bugs and bad configs. They do not replace token issuance, audience checks, step-up, or revocation. Here…
CVE-2026-95503 lets an adjacent-network attacker spoof the KDC when Keycloak does Kerberos password authentication without SPNEGO. No fixed release yet.
The CLOUD Act follows the provider, not the datacentre. What that means for Keycloak in the EU, and the questions…
Get tutorials, product updates, and Keycloak tips delivered to your inbox.