Red Hat Keycloak updates close account-takeover paths across two release streams
Critical updates cover the 26.6 and 26.4 streams across standalone packages and OpenShift images, with the newer stream also fixing secret exposure and privilege boundaries.
Red Hat has issued Critical security updates for two Red Hat build of Keycloak release streams. The 26.6.6 standalone-package advisory lists five vulnerabilities, including an unauthenticated reset-credentials bypass and a predictable account-linking hash that could be used through a malicious OIDC client.
The older 26.4 stream receives 26.4.15 packages for the unauthenticated reset-credentials flaw. Red Hat also published aligned OpenShift server and Operator images for 26.6.6 and 26.4.15. The update therefore spans conventional installations and clusters managed on OpenShift.
What changed
The two account-takeover issues are the sharpest part of the 26.6.6 release. CVE-2026-18963 concerns an unauthenticated bypass in the reset-credentials flow. CVE-2026-15571 concerns a predictable account-linking hash that enables takeover through a malicious OIDC client.
The remaining 26.6.6 fixes cover distinct authorization and secret-handling boundaries. CVE-2026-17048 addresses rotated client secrets resolved from a vault being exposed through the Admin REST API. CVE-2026-9796 fixes a time-of-check to time-of-use privilege-escalation flaw. CVE-2026-14613 prevents an FGAP v2 role-groups endpoint from disclosing hidden group metadata without group-view permission.
For 26.4.15, Red Hat’s standalone advisory and image advisory describe the reset-credentials bypass, CVE-2026-18963. All four advisories were issued August 18 and carry Critical severity.
Who is affected
Teams operating Red Hat build of Keycloak should identify both their release stream and delivery path. The package advisories apply to standalone server installations. The image advisories cover Keycloak server and Operator images for OpenShift Container Platform in the corresponding 26.6.6 and 26.4.15 streams.
Identity services expose high-value flows: credential reset, external identity-provider linking, administrative APIs and authorization checks. Deployments that expose the affected paths should treat these updates as immediate maintenance items rather than routine point releases.
What to do
Red Hat’s stated preparation step is to back up the existing installation before applying an update, including applications, configuration files, databases and database settings. Operators should then select the fixed packages or the updated server and Operator images that match their stream and deployment model.
After rollout, teams should verify credential-reset and brokered-login paths as well as administrative integrations that retrieve client configuration. The advisories do not describe those checks as substitutes for updating; they are practical validation around a Critical identity-system change.
sources
- RHSA-2026:56523 — Critical Red Hat build of Keycloak 26.6.6 Security Updateaccess.redhat.com
- RHSA-2026:56524 — Critical Red Hat build of Keycloak 26.6.6 Images Security Updateaccess.redhat.com
- RHSA-2026:56520 — Critical Red Hat build of Keycloak 26.4.15 Security Updateaccess.redhat.com
- RHSA-2026:56519 — Critical Red Hat build of Keycloak 26.4.15 Images Security Updateaccess.redhat.com
comments · 0