Blog

Insights on Identity, Security & Keycloak

Tutorials, deep dives, and best practices from the Skycloak team.

Articles

AWS Cognito Pricing as You Scale: Is It Still the Right Fit?

AWS Cognito pricing tracks monthly active users, and enterprise SSO users get a free tier of only 50. Three checks…

Guilliano Molaire Guilliano Molaire 9 min read
security

MCP Python SDK OAuth Flaw: Pin the Issuer on Keycloak

MCP OAuth flaw GHSA-qx49-fqc8-xw99: a malicious server could steal client secrets and PKCE verifiers from the MCP Python SDK. Upgrade,…

Guilliano Molaire Guilliano Molaire 12 min read
Articles

Why SSO Alone Won’t Pass a Vendor Security Review

SSO answers one line of a vendor security review. What reviewers also check: enforced SSO, deprovisioning, sessions, audit logs, and…

Guilliano Molaire Guilliano Molaire 9 min read
security

CVE-2026-100606: Flowise SSO Invite Takeover and IdP Checks

CVE-2026-100606 lets anyone who signs in with an invitee's email take over a pending Flowise Enterprise invite. How it works…

Guilliano Molaire Guilliano Molaire 10 min read
Articles

SOC 2 Type 1 vs Type 2: Which Do You Need First?

SOC 2 Type 1 vs Type 2: Type 1 checks control design on one date, Type 2 checks controls worked…

Guilliano Molaire Guilliano Molaire 8 min read
security

JADEPUFFER and Storm-3168: Retire Static Keycloak Secrets

Storm-3168 (JADEPUFFER) wiped Azure resources with compromised service principals. How the same client secret risk looks on Keycloak, and how…

Guilliano Molaire Guilliano Molaire 12 min read
security

CVE-2026-96448: Keycloak FGAP Composite Privilege Escalation

CVE-2026-96448 is a Keycloak privilege escalation: an FGAP v2 delegated admin assigns a composite role that hides realm-admin. How it…

Guilliano Molaire Guilliano Molaire 12 min read
security

Keycloak 26.7.4 Security Fixes: A Self-Hosted Patch Checklist

Keycloak 26.7.4 fixes six CVEs, from a SAML memory leak to impersonation of realm admins. Which reach 26.6 and 26.4,…

Guilliano Molaire Guilliano Molaire 10 min read
security

CVE-2026-19607: Keycloak Username Takeover and Account Lockout

CVE-2026-19607: a brokered login whose email matches a Keycloak username shadows that user and locks them out. Fixed in 26.7.4.…

Guilliano Molaire Guilliano Molaire 11 min read
security

CVE-2026-97176: Keycloak Step-Up Authentication Bypass

CVE-2026-97176 can let Keycloak issue a token at a lower assurance level than a client's essential acr demands, skipping step-up.…

Guilliano Molaire Guilliano Molaire 9 min read

Stay ahead on identity & security

Get tutorials, product updates, and Keycloak tips delivered to your inbox.

© 2026 Skycloak. All Rights Reserved. Design by Yasser Soliman