Articles tagged with keycloak.
An introduction to issuing Verifiable Credentials from Keycloak with OID4VCI: what the standard is, Keycloak's experimental support, and how it…
CVE-2026-5430 let forged JWTs past WSO2 API Manager authentication. Here is how you pin algorithms and fail closed on APIs…
Microsoft Entra Agent ID gives AI agents directory identities. Here is how blueprints, FIC and agent OBO map to Keycloak…
Okta Agent Gateway puts policy inline between AI agents and MCP tools. Here is what it adds, and why MCP…
MCP OAuth flaw GHSA-qx49-fqc8-xw99: a malicious server could steal client secrets and PKCE verifiers from the MCP Python SDK. Upgrade,…
CVE-2026-100606 lets anyone who signs in with an invitee's email take over a pending Flowise Enterprise invite. How it works…
Storm-3168 (JADEPUFFER) wiped Azure resources with compromised service principals. How the same client secret risk looks on Keycloak, and how…
CVE-2026-96448 is a Keycloak privilege escalation: an FGAP v2 delegated admin assigns a composite role that hides realm-admin. How it…
Keycloak 26.7.4 fixes six CVEs, from a SAML memory leak to impersonation of realm admins. Which reach 26.6 and 26.4,…
CVE-2026-19607: a brokered login whose email matches a Keycloak username shadows that user and locks them out. Fixed in 26.7.4.…
Get tutorials, product updates, and Keycloak tips delivered to your inbox.