Red Hat Security Advisory: Red Hat build of Keycloak 26.4.9 Images Security Update
🔗 CVE IDs covered (6)
📋 Description
CVE-2025-13881 — org.keycloak.services.resources.admin: Keycloak: Limited administrator can retrieve sensitive user attributes via Admin API CVE-2025-14559 — org.keycloak/keycloak-services: Keycloak keycloak-services: Business logic flaw allows unauthorized token issuance for disabled users CVE-2025-14778 — keycloak: Incorrect ownership checks in /uma-policy/ CVE-2026-0871 — org.keycloak/keycloak-services: Keycloak: Unauthorized modification of unmanaged user attributes by administrators CVE-2026-1486 — org.keycloak.protocol.oidc.grants: Disabled identity providers are still accepted for JWT Authorization Grant CVE-2026-1529 — org.keycloak.services.resources.organizations: Keycloak: Unauthorized organization registration via improper invitation token validation
🎯 Affected products10
- Red Hat build of Keycloak 26.4
- rhbk/keycloak-operator-bundle@sha256:fd235c7a4820865af18c35441296ae7d40bbd2eea2f7c7b16d5ce9f658c5653b_amd64 as a component of Red Hat build of Keycloak 26.4
- rhbk/keycloak-rhel9-operator@sha256:3fb03c48b66c39429e64eb4f20a110fea755e102285778aae0a8229cb5681be1_s390x as a component of Red Hat build of Keycloak 26.4
- rhbk/keycloak-rhel9-operator@sha256:718d63c9de563c7339fc6800d7f014c186467b11b2c9b058f88fa9883283180b_arm64 as a component of Red Hat build of Keycloak 26.4
- rhbk/keycloak-rhel9-operator@sha256:aa64ecc958ea5569ba023b51d7df1bbc347f7df459a92a23e8b058ae4622b6d4_amd64 as a component of Red Hat build of Keycloak 26.4
- rhbk/keycloak-rhel9-operator@sha256:bcc01dface0582789dae5eb2919ac8ba5a4f5e3e36909a7983a32a0a05d14ae0_ppc64le as a component of Red Hat build of Keycloak 26.4
- rhbk/keycloak-rhel9@sha256:3f38533ab14d09b0d86394d73a61f3304eef2a19a65e5d5cf87107794d4fc23b_s390x as a component of Red Hat build of Keycloak 26.4
- rhbk/keycloak-rhel9@sha256:71fbf006f8e158fe29b47dfce09757bb004715395c5063b8e317ffd5ef437112_amd64 as a component of Red Hat build of Keycloak 26.4
- rhbk/keycloak-rhel9@sha256:7d3668580a61da509f7b473f8df9197548fb71c465eeaaa53802e7d4e99b84fd_ppc64le as a component of Red Hat build of Keycloak 26.4
- rhbk/keycloak-rhel9@sha256:8df9fbf1320938c3e708241c78796bcc832d1a11b85be78dd37bbc54630e6365_arm64 as a component of Red Hat build of Keycloak 26.4
✅ Remediation
Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, disable the Token Exchange preview feature within your Keycloak deployment if it is not actively required. This can typically be achieved through Keycloak's administrative console or by adjusting relevant configuration settings. If the Token Exchange feature must remain enabled, ensure that only strictly necessary and highly trusted clients are granted the 'impersonation' permission. Any changes to Keycloak configuration may require a service restart or reload to take effect, which could temporarily impact service availability. Workaround: To mitigate this issue, administrators should immediately revoke or rotate the signing keys associated with any Identity Provider that has been disabled in Keycloak. This operational control is crucial to prevent unauthorized token issuance by ensuring that compromised or offboarded IdP keys cannot be used to generate valid JWT assertions. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.