Tag

keycloak

Articles tagged with keycloak.

Definition and Basics

Issuing Verifiable Credentials With Keycloak (OID4VCI)

An introduction to issuing Verifiable Credentials from Keycloak with OID4VCI: what the standard is, Keycloak's experimental support, and how it…

Guilliano Molaire Guilliano Molaire 12 min read
security

CVE-2026-5430: WSO2 JWT Bypass and Your Keycloak APIs

CVE-2026-5430 let forged JWTs past WSO2 API Manager authentication. Here is how you pin algorithms and fail closed on APIs…

Guilliano Molaire Guilliano Molaire 13 min read
comparisons

Microsoft Entra Agent ID vs Keycloak for AI Agent Identity

Microsoft Entra Agent ID gives AI agents directory identities. Here is how blueprints, FIC and agent OBO map to Keycloak…

Guilliano Molaire Guilliano Molaire 13 min read
comparisons

Okta Agent Gateway vs Keycloak for MCP Authorization

Okta Agent Gateway puts policy inline between AI agents and MCP tools. Here is what it adds, and why MCP…

Guilliano Molaire Guilliano Molaire 12 min read
security

MCP Python SDK OAuth Flaw: Pin the Issuer on Keycloak

MCP OAuth flaw GHSA-qx49-fqc8-xw99: a malicious server could steal client secrets and PKCE verifiers from the MCP Python SDK. Upgrade,…

Guilliano Molaire Guilliano Molaire 12 min read
security

CVE-2026-100606: Flowise SSO Invite Takeover and IdP Checks

CVE-2026-100606 lets anyone who signs in with an invitee's email take over a pending Flowise Enterprise invite. How it works…

Guilliano Molaire Guilliano Molaire 10 min read
security

JADEPUFFER and Storm-3168: Retire Static Keycloak Secrets

Storm-3168 (JADEPUFFER) wiped Azure resources with compromised service principals. How the same client secret risk looks on Keycloak, and how…

Guilliano Molaire Guilliano Molaire 12 min read
security

CVE-2026-96448: Keycloak FGAP Composite Privilege Escalation

CVE-2026-96448 is a Keycloak privilege escalation: an FGAP v2 delegated admin assigns a composite role that hides realm-admin. How it…

Guilliano Molaire Guilliano Molaire 12 min read
security

Keycloak 26.7.4 Security Fixes: A Self-Hosted Patch Checklist

Keycloak 26.7.4 fixes six CVEs, from a SAML memory leak to impersonation of realm admins. Which reach 26.6 and 26.4,…

Guilliano Molaire Guilliano Molaire 10 min read
security

CVE-2026-19607: Keycloak Username Takeover and Account Lockout

CVE-2026-19607: a brokered login whose email matches a Keycloak username shadows that user and locks them out. Fixed in 26.7.4.…

Guilliano Molaire Guilliano Molaire 11 min read

Stay ahead on identity & security

Get tutorials, product updates, and Keycloak tips delivered to your inbox.

© 2026 Skycloak. All Rights Reserved. Design by Yasser Soliman