Tag

keycloak

Articles tagged with keycloak.

security

CVE-2026-17048: Keycloak’s Admin REST API Can Hand Back a Vault-Resolved Client Secret

CVE-2026-17048 lets a view-only Keycloak admin read the plaintext of a vault-backed rotated client secret. CVSS 5.5, fixed in 26.7.2…

Guilliano Molaire Guilliano Molaire 9 min read
comparisons

Agentic IAM in September 2026: What Okta Agent SSO, Ping, and JumpCloud Mean If You Run Keycloak

Okta, Ping and JumpCloud all shipped agentic IAM in the last three weeks. Here is what those launches actually add,…

Guilliano Molaire Guilliano Molaire 11 min read
keycloak-operations

Keycloak Native SCIM API Preview in 26.7: What It Covers, What It Misses, and When Managed Still Wins

Keycloak 26.7 promotes its native SCIM API to preview behind the scim-api flag. It handles CRUD, PATCH and filtering, but…

Guilliano Molaire Guilliano Molaire 9 min read
security

CVE-2026-88770: Keycloak’s Device Flow Can Still Issue Tokens for a Locked Account

CVE-2026-88770 lets Keycloak's device authorization grant redeem tokens for an account brute-force protection already locked. CVSS 6.5, no patch yet.

Guilliano Molaire Guilliano Molaire 8 min read
security

CVE-2026-18963: The Keycloak Password Reset Takeover, and Which Versions Fix It

CVE-2026-18963 lets an unauthenticated attacker take over any Keycloak account through the reset-credentials flow. CVSS 9.1. Three release lines carry…

Guilliano Molaire Guilliano Molaire 10 min read
security

CVE-2026-82968: Hardening Keycloak First-Broker Login While the Fix Is Pending

CVE-2026-82968 lets an attacker on the same social provider intercept Keycloak account linking. CVSS 6.4, no patched release yet. What…

Guilliano Molaire Guilliano Molaire 8 min read
security

Keycloak 26.7.3 Security Fixes: A Self-Hosted Patch Checklist

Keycloak 26.7.3 fixes twenty CVEs across FGAP v2, OIDC and token exchange. What to re-test after you upgrade, and which…

Guilliano Molaire Guilliano Molaire 9 min read
security

Keycloak LDAP Certificate Validation: What CVE-2026-35563 Actually Affects

CVE-2026-35563 is scoped to a Keycloak test dependency, not LDAP user federation. Here is what really governs LDAP certificate validation…

Guilliano Molaire Guilliano Molaire 7 min read
security

CVE-2026-16072 and CVE-2026-18201: Two Keycloak Organization Permission Gaps

Two moderate Keycloak CVEs let admins act outside their permissions on organizations. What they allow, who is affected, and what…

Guilliano Molaire Guilliano Molaire 7 min read
Authentication Error Handling: User Experience and Security Balance
Tutorials

Keycloak Authentication Error Handling: Custom Error Pages

Customize Keycloak error pages, handle OAuth/OIDC errors in your app, and configure brute force protection for secure, user-friendly authentication.

Guilliano Molaire Guilliano Molaire 11 min read

Stay ahead on identity & security

Get tutorials, product updates, and Keycloak tips delivered to your inbox.

© 2026 Skycloak. All Rights Reserved. Design by Yasser Soliman