live wire
AI · Red Hat documents usage-based admission fair sharing for Kueue 1.4 on OpenShiftRed Hat DeveloperAI: Red Hat maps governed firewall changes from ServiceNow through Ansible and two human approval gatesRed Hat DeveloperCLUSTER MGMT · ACM 2.17 makes Submariner 0.24 GA with Important-rated fixesRed Hat ErrataPLATFORM · Red Hat makes on-premises Lightspeed recommendations GA for Satellite 6.18Red Hat ErrataSECURITY · Red Hat Hardened Images updates Tomcat 10 for nine authentication, access-control and DoS flawsRed Hat ErrataAI · Open Data Hub 3.6.0 EA1 bundles Trainer, MLflow and llm-d componentsOpen Data HubAI · Speculators 0.6.0 adds P-EAGLE parallel drafting for vLLM speculative decodingRed Hat DeveloperSECURITY · OpenShift 4.17.57 fixes seven Go and TLS CVEs in an Important-rated updateRed Hat ErrataAI · Red Hat benchmarks local LLM guardrails with EvalHub, exposing regex accuracy and latency trade-offsRed Hat DeveloperAI · Red Hat maps silent tool-call failures across agentic pipelinesRed HatAPI · Kuadrant 1.5.3 adds GRPCRoute policies and developer-portal API-key workflowsKuadrantAI · (Aug 25) IBM releases Apache-2.0 Granite 4.2 reasoning models in 3B, 8B and 30B sizesIBM ResearchJAVA · Red Hat build of Quarkus 3.33.3.SP1 fixes 13 CVEs in an Important-rated updateRed Hat errataAI · vLLM moves Kimi K2 RL weight sync across 384 H100s in 7.53 seconds (Aug 22)vLLMAI · Red Hat documents usage-based admission fair sharing for Kueue 1.4 on OpenShiftRed Hat DeveloperAI: Red Hat maps governed firewall changes from ServiceNow through Ansible and two human approval gatesRed Hat DeveloperCLUSTER MGMT · ACM 2.17 makes Submariner 0.24 GA with Important-rated fixesRed Hat ErrataPLATFORM · Red Hat makes on-premises Lightspeed recommendations GA for Satellite 6.18Red Hat ErrataSECURITY · Red Hat Hardened Images updates Tomcat 10 for nine authentication, access-control and DoS flawsRed Hat ErrataAI · Open Data Hub 3.6.0 EA1 bundles Trainer, MLflow and llm-d componentsOpen Data HubAI · Speculators 0.6.0 adds P-EAGLE parallel drafting for vLLM speculative decodingRed Hat DeveloperSECURITY · OpenShift 4.17.57 fixes seven Go and TLS CVEs in an Important-rated updateRed Hat ErrataAI · Red Hat benchmarks local LLM guardrails with EvalHub, exposing regex accuracy and latency trade-offsRed Hat DeveloperAI · Red Hat maps silent tool-call failures across agentic pipelinesRed HatAPI · Kuadrant 1.5.3 adds GRPCRoute policies and developer-portal API-key workflowsKuadrantAI · (Aug 25) IBM releases Apache-2.0 Granite 4.2 reasoning models in 3B, 8B and 30B sizesIBM ResearchJAVA · Red Hat build of Quarkus 3.33.3.SP1 fixes 13 CVEs in an Important-rated updateRed Hat errataAI · vLLM moves Kimi K2 RL weight sync across 384 H100s in 7.53 seconds (Aug 22)vLLM
upstreambeat.ai
releaseIDENTITY

Red Hat Keycloak updates close account-takeover paths across two release streams

Critical updates cover the 26.6 and 26.4 streams across standalone packages and OpenShift images, with the newer stream also fixing secret exposure and privilege boundaries.

By The News Desk· Aug 18, 2026

Red Hat has issued Critical security updates for two Red Hat build of Keycloak release streams. The 26.6.6 standalone-package advisory lists five vulnerabilities, including an unauthenticated reset-credentials bypass and a predictable account-linking hash that could be used through a malicious OIDC client.

The older 26.4 stream receives 26.4.15 packages for the unauthenticated reset-credentials flaw. Red Hat also published aligned OpenShift server and Operator images for 26.6.6 and 26.4.15. The update therefore spans conventional installations and clusters managed on OpenShift.

What changed

The two account-takeover issues are the sharpest part of the 26.6.6 release. CVE-2026-18963 concerns an unauthenticated bypass in the reset-credentials flow. CVE-2026-15571 concerns a predictable account-linking hash that enables takeover through a malicious OIDC client.

The remaining 26.6.6 fixes cover distinct authorization and secret-handling boundaries. CVE-2026-17048 addresses rotated client secrets resolved from a vault being exposed through the Admin REST API. CVE-2026-9796 fixes a time-of-check to time-of-use privilege-escalation flaw. CVE-2026-14613 prevents an FGAP v2 role-groups endpoint from disclosing hidden group metadata without group-view permission.

For 26.4.15, Red Hat’s standalone advisory and image advisory describe the reset-credentials bypass, CVE-2026-18963. All four advisories were issued August 18 and carry Critical severity.

Who is affected

Teams operating Red Hat build of Keycloak should identify both their release stream and delivery path. The package advisories apply to standalone server installations. The image advisories cover Keycloak server and Operator images for OpenShift Container Platform in the corresponding 26.6.6 and 26.4.15 streams.

Identity services expose high-value flows: credential reset, external identity-provider linking, administrative APIs and authorization checks. Deployments that expose the affected paths should treat these updates as immediate maintenance items rather than routine point releases.

What to do

Red Hat’s stated preparation step is to back up the existing installation before applying an update, including applications, configuration files, databases and database settings. Operators should then select the fixed packages or the updated server and Operator images that match their stream and deployment model.

After rollout, teams should verify credential-reset and brokered-login paths as well as administrative integrations that retrieve client configuration. The advisories do not describe those checks as substitutes for updating; they are practical validation around a Critical identity-system change.

Filed by The News Desk. Corrections: desk@upstreambeat.ai · Our standards →

comments · 0

    Comments are moderated before they appear. Your email is used once to confirm it is you — never shown, never sold. Corrections and questions get an answer from the desk when we have one.