Red Hat Security Advisory: Red Hat build of Keycloak 26.4.9 Images Security Update
Red Hat has released a security advisory for the Red Hat build of Keycloak 26.4.9 images used on OpenShift Container Platform. The update addresses multiple security vulnerabilities including improper invitation token validation, acceptance of disabled identity providers for JWT authorization, incorrect ownership checks, unauthorized modification of user attributes, unauthorized token issuance for disabled users, and exposure of sensitive user attributes via the Admin API. These issues could allow unauthorized access or privilege escalation within Keycloak deployments. The advisory provides updated container images to remediate these vulnerabilities.
AI Analysis
Technical Summary
This security advisory covers multiple vulnerabilities in Red Hat build of Keycloak 26.4.9, an integrated sign-on solution for OpenShift. The fixed issues include: CVE-2026-1529 (unauthorized organization registration due to improper invitation token validation), CVE-2026-1486 (disabled identity providers accepted for JWT Authorization Grant), CVE-2025-14778 (incorrect ownership checks in /uma-policy/), CVE-2026-0871 (unauthorized modification of unmanaged user attributes by administrators), CVE-2025-14559 (business logic flaw allowing unauthorized token issuance for disabled users), and CVE-2025-13881 (limited administrators retrieving sensitive user attributes via Admin API). The advisory releases new container images aligned with the standalone product release to address these issues for on-premise or private cloud deployments on OpenShift Container Platform.
Potential Impact
The vulnerabilities collectively could allow unauthorized users or limited administrators to register organizations, bypass disabled identity provider restrictions, modify user attributes without authorization, issue tokens improperly, and access sensitive user information. This could lead to privilege escalation, unauthorized access to protected resources, and potential compromise of authentication and authorization mechanisms within affected Keycloak deployments.
Mitigation Recommendations
Red Hat has released updated container images for Red Hat build of Keycloak 26.4.9 and its Operator to address these vulnerabilities. Users should back up their existing installations, including applications, configurations, and databases, before applying the update. Applying the updated images is the recommended remediation. No alternative mitigations or workarounds are specified in the advisory.
Red Hat Security Advisory: Red Hat build of Keycloak 26.4.9 Images Security Update
Description
Red Hat has released a security advisory for the Red Hat build of Keycloak 26.4.9 images used on OpenShift Container Platform. The update addresses multiple security vulnerabilities including improper invitation token validation, acceptance of disabled identity providers for JWT authorization, incorrect ownership checks, unauthorized modification of user attributes, unauthorized token issuance for disabled users, and exposure of sensitive user attributes via the Admin API. These issues could allow unauthorized access or privilege escalation within Keycloak deployments. The advisory provides updated container images to remediate these vulnerabilities.
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This security advisory covers multiple vulnerabilities in Red Hat build of Keycloak 26.4.9, an integrated sign-on solution for OpenShift. The fixed issues include: CVE-2026-1529 (unauthorized organization registration due to improper invitation token validation), CVE-2026-1486 (disabled identity providers accepted for JWT Authorization Grant), CVE-2025-14778 (incorrect ownership checks in /uma-policy/), CVE-2026-0871 (unauthorized modification of unmanaged user attributes by administrators), CVE-2025-14559 (business logic flaw allowing unauthorized token issuance for disabled users), and CVE-2025-13881 (limited administrators retrieving sensitive user attributes via Admin API). The advisory releases new container images aligned with the standalone product release to address these issues for on-premise or private cloud deployments on OpenShift Container Platform.
Potential Impact
The vulnerabilities collectively could allow unauthorized users or limited administrators to register organizations, bypass disabled identity provider restrictions, modify user attributes without authorization, issue tokens improperly, and access sensitive user information. This could lead to privilege escalation, unauthorized access to protected resources, and potential compromise of authentication and authorization mechanisms within affected Keycloak deployments.
Mitigation Recommendations
Red Hat has released updated container images for Red Hat build of Keycloak 26.4.9 and its Operator to address these vulnerabilities. Users should back up their existing installations, including applications, configurations, and databases, before applying the update. Applying the updated images is the recommended remediation. No alternative mitigations or workarounds are specified in the advisory.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:2366
- Cve Count
- 6
- Additional Cves
- ["CVE-2025-14559","CVE-2025-14778","CVE-2026-0871","CVE-2026-1486","CVE-2026-1529"]
Threat ID: 6a3c0cefeed863c81e2386cf
Added to database: 06/24/2026, 16:59:27 UTC
Last enriched: 08/10/2026, 20:34:27 UTC
Last updated: 09/10/2026, 19:36:49 UTC
Views: 23
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.