Details:
Red Hat build of Keycloak 26.4.16 is a standalone server, based on
the Keycloak project, that provides authentication and
standards-based single sign-on capabilities for web and mobile
applications.
Security fixes:
- Privilege escalation via impersonation role allows takeover of realm administrator accounts (CVE-2026-17526)
- SAML Redirect DEFLATE helpers leak native zlib state (CVE-2026-18212)
- Broker-originated username collision causes account lockout (CVE-2026-19607)
- Incomplete fix for arbitrary filesystem path probing via keystore parameters (CVE-2026-19729)
- TLS hostname verification bypass via OpenSSL client path misconfiguration (CVE-2026-62243)
- Incomplete fix for CVE-2026-15573 allows policy enforcer bypass via percent-encoded URI segments (CVE-2026-74909)
- unauthenticated DoS via unbounded locale caching (CVE-2026-79651)