Articles about security from the Skycloak team.
Okta widened shadow AI agent discovery at Oktane 2026. Keycloak has no endpoint scanner, but it owns the chokepoint where…
Keycloak 26.x ships no push authenticator, so MFA fatigue lands differently here. The exposure that matters is authenticator enrollment, and…
CVE-2026-17526 let a Keycloak impersonation-role holder take over a realm admin. Fixed in 26.7.4 on 16 September 2026, and on…
CVE-2026-59822 let any fabricated Bearer token open a LiteLLM MCP session. The two separate bugs one pull request closed, and…
Keycloak checks an audience client is enabled during token exchange, but not when that refresh token is used. What CVE-2026-93999…
Microsoft's September 2026 report shows passkey-themed lures driving AiTM and device-code attacks. Here is the Keycloak realm hardening that answers…
CVE-2026-17048 lets a view-only Keycloak admin read the plaintext of a vault-backed rotated client secret. CVSS 5.5, fixed in 26.7.2…
CVE-2026-88770 lets Keycloak's device authorization grant redeem tokens for an account brute-force protection already locked. CVSS 6.5, no patch yet.
CVE-2026-18963 lets an unauthenticated attacker take over any Keycloak account through the reset-credentials flow. CVSS 9.1. Three release lines carry…
CVE-2026-82968 lets an attacker on the same social provider intercept Keycloak account linking. CVSS 6.4, no patched release yet. What…
Get tutorials, product updates, and Keycloak tips delivered to your inbox.