Red Hat Security Advisory: Red Hat build of Keycloak 26.6.6 Security Update
Description
Red Hat has issued a critical security update for its build of Keycloak 26.6.6, addressing multiple vulnerabilities including privilege escalation via a TOCTOU flaw, unauthenticated account takeover, information disclosure, and predictable hashes enabling account takeover. The update fixes five CVEs affecting authentication and authorization components. Users are advised to back up their installations before applying the update.
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Red Hat build of Keycloak 26.6.6, a standalone authentication and single sign-on server, contains several critical security vulnerabilities. These include CVE-2026-9796, a Time-of-Check to Time-of-Use (TOCTOU) privilege escalation vulnerability; CVE-2026-18963, an unauthenticated account takeover via reset-credentials flow bypass; CVE-2026-17048, leakage of vault-resolved rotated client secrets via the Admin REST API; CVE-2026-15571, predictable account-linking hashes enabling account takeover via malicious OIDC clients; and CVE-2026-14613, disclosure of hidden group metadata without proper group view permissions. Red Hat has released updated packages to address these issues.
Potential Impact
Successful exploitation of these vulnerabilities could allow attackers to escalate privileges, take over user accounts without authentication, leak sensitive client secrets, and access hidden group metadata without authorization. This compromises the confidentiality, integrity, and availability of authentication services provided by Keycloak, potentially impacting all applications relying on it for identity management.
Mitigation Recommendations
Red Hat has released updated packages for the Red Hat build of Keycloak 26.6.6 that address these vulnerabilities. Users should back up their existing installations, including applications, configuration files, and databases, before applying the update. Applying the official update from Red Hat is the recommended remediation. No alternative mitigations or workarounds are indicated in the advisory.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:56523
- Cve Count
- 5
- Additional Cves
- ["CVE-2026-14613","CVE-2026-15571","CVE-2026-17048","CVE-2026-18963"]
- State
- PUBLISHED
Threat ID: 6a870a71acd9273b49b589fd
Added to database: 08/20/2026, 14:08:49 UTC
Last enriched: 09/11/2026, 00:02:23 UTC
Last updated: 10/05/2026, 06:48:20 UTC
Views: 156
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.