live wire
AI · Red Hat documents usage-based admission fair sharing for Kueue 1.4 on OpenShiftRed Hat DeveloperAI: Red Hat maps governed firewall changes from ServiceNow through Ansible and two human approval gatesRed Hat DeveloperCLUSTER MGMT · ACM 2.17 makes Submariner 0.24 GA with Important-rated fixesRed Hat ErrataPLATFORM · Red Hat makes on-premises Lightspeed recommendations GA for Satellite 6.18Red Hat ErrataSECURITY · Red Hat Hardened Images updates Tomcat 10 for nine authentication, access-control and DoS flawsRed Hat ErrataAI · Open Data Hub 3.6.0 EA1 bundles Trainer, MLflow and llm-d componentsOpen Data HubAI · Speculators 0.6.0 adds P-EAGLE parallel drafting for vLLM speculative decodingRed Hat DeveloperSECURITY · OpenShift 4.17.57 fixes seven Go and TLS CVEs in an Important-rated updateRed Hat ErrataAI · Red Hat benchmarks local LLM guardrails with EvalHub, exposing regex accuracy and latency trade-offsRed Hat DeveloperAI · Red Hat maps silent tool-call failures across agentic pipelinesRed HatAPI · Kuadrant 1.5.3 adds GRPCRoute policies and developer-portal API-key workflowsKuadrantAI · (Aug 25) IBM releases Apache-2.0 Granite 4.2 reasoning models in 3B, 8B and 30B sizesIBM ResearchJAVA · Red Hat build of Quarkus 3.33.3.SP1 fixes 13 CVEs in an Important-rated updateRed Hat errataAI · vLLM moves Kimi K2 RL weight sync across 384 H100s in 7.53 seconds (Aug 22)vLLMAI · Red Hat documents usage-based admission fair sharing for Kueue 1.4 on OpenShiftRed Hat DeveloperAI: Red Hat maps governed firewall changes from ServiceNow through Ansible and two human approval gatesRed Hat DeveloperCLUSTER MGMT · ACM 2.17 makes Submariner 0.24 GA with Important-rated fixesRed Hat ErrataPLATFORM · Red Hat makes on-premises Lightspeed recommendations GA for Satellite 6.18Red Hat ErrataSECURITY · Red Hat Hardened Images updates Tomcat 10 for nine authentication, access-control and DoS flawsRed Hat ErrataAI · Open Data Hub 3.6.0 EA1 bundles Trainer, MLflow and llm-d componentsOpen Data HubAI · Speculators 0.6.0 adds P-EAGLE parallel drafting for vLLM speculative decodingRed Hat DeveloperSECURITY · OpenShift 4.17.57 fixes seven Go and TLS CVEs in an Important-rated updateRed Hat ErrataAI · Red Hat benchmarks local LLM guardrails with EvalHub, exposing regex accuracy and latency trade-offsRed Hat DeveloperAI · Red Hat maps silent tool-call failures across agentic pipelinesRed HatAPI · Kuadrant 1.5.3 adds GRPCRoute policies and developer-portal API-key workflowsKuadrantAI · (Aug 25) IBM releases Apache-2.0 Granite 4.2 reasoning models in 3B, 8B and 30B sizesIBM ResearchJAVA · Red Hat build of Quarkus 3.33.3.SP1 fixes 13 CVEs in an Important-rated updateRed Hat errataAI · vLLM moves Kimi K2 RL weight sync across 384 H100s in 7.53 seconds (Aug 22)vLLM
upstreambeat.ai
releaseIDENTITY

Keycloak 26.7.3 closes 20 security flaws across identity and administration paths

The upstream identity release addresses OIDC policy bypasses, delegated-admin authorization gaps, token-exchange restrictions and an incomplete path-traversal fix.

Security fixes across Keycloak identity and admin features.
Chart: figures from the story
By The News Desk· Aug 31, 2026the quick take — two AI hosts, this story only

Keycloak 26.7.3 is a security-heavy maintenance release: its release notes list 20 CVEs alongside six additional weaknesses and a set of bug fixes. The affected areas span OIDC, token exchange, organizations, fine-grained administrative permissions, authorization services and the server core.

What changed

Several fixes close paths where configured identity policy could be bypassed. CVE-2026-16093 addresses unsigned assertion headers being accepted despite a required signed-JWT assertion policy. CVE-2026-16089 fixes authorization codes that could be retargeted to another client session, while CVE-2026-18218 restores client-level not-before revocation behavior in a particular realm configuration.

The release also tightens external access-token exchange. Separate fixes prevent Microsoft tenant restrictions and Google hosted-domain restrictions from being bypassed. Another OIDC fix completes earlier work on response-parameter injection by checking forbidden parameters in URL fragments as well as query strings.

Delegated administration is another major cluster. The notes describe fixes for removing privileged composite roles, assigning users to unpermitted groups, creating managed organization members without the required permission, exposing hidden groups or client-role metadata, and returning user personally identifiable information without the expected per-user filter.

Keycloak 26.7.3 also includes an incomplete-fix correction for CVE-2026-9083, where relative path traversal could still enable filesystem probing in 26.6.4. The release separately addresses LDAP hostname verification, exposed reCAPTCHA secrets, UMA time-policy handling and consent enforcement for the JWT bearer authorization grant.

Who is affected

Operators should pay particular attention if they use fine-grained admin permissions v2, organizations, external identity-provider token exchange, JWT assertions, UMA authorization services or delegated realm administration. Deployments relying on client revocation controls or strict redirect handling also intersect directly with the corrected paths listed in the release.

The notes do not assign severity ratings on the release page, so this desk is not inferring exploitability or impact beyond the behaviors Keycloak documents. The breadth of identity and authorization controls affected is nevertheless enough to make this more than a routine point release.

What to do

Keycloak points users to the 26.7.3 download and tells operators to consult the migration guide before upgrading. Teams should map the listed CVEs to enabled features, prioritize internet-facing and delegated-admin deployments, and validate authentication, token exchange and administrative workflows after the update.

Because the release also fixes a sustained high-CPU regression and super-linear admin API cost growth introduced in earlier 26.7 builds, performance-sensitive installations should include those paths in post-upgrade checks.

sources

Filed by The News Desk. Corrections: desk@upstreambeat.ai · Our standards →

comments · 0

    Comments are moderated before they appear. Your email is used once to confirm it is you — never shown, never sold. Corrections and questions get an answer from the desk when we have one.