Keycloak Advisory Watch

Archives
Log in
Subscribe
September 17, 2026

Keycloak advisory batch 2026-09-16: 1 advisory, 1 high or critical — what clears them

Keycloak published 1 advisory on 2026-09-16 — 1 rated high or critical. Here is the batch, the patched versions it shipped per maintained line, and what we have seen break on the way there.

The coverage table has one column. 26.7.4 is the only release this batch names. An install on an earlier line has no patched version listed, so getting current is the remediation.

The batch

CVE Severity Summary Advisory
CVE-2026-90997 High Replay protection bypass leads to unauthorized access via database driver semantics mismatch advisory

What clears it

CVE 26.7.x
CVE-2026-90997 26.7.4
  • On 26.7.x: the highest patched version in this batch is 26.7.4, covering 1 of 1 advisory.

A dash means the advisory lists no patched version on that line. It does not mean the line is safe, and it does not mean it is exposed — it means the advisory does not say, and the page is the place to find out.

What breaks on the way there

26.7.x to 26.7.4. We have not rehearsed this hop. 26.7.4 shipped with the advisory and our matrix targets 26.7.3, so everything below is the neighbouring hop rather than this one.

We measured 26.7.1 to 26.7.3 three times. No Liquibase changesets, 24 seconds from stop to ready, index audit 119 of 119, realm config intact at 1,000 users (2026-08-31-26.7.1-to-26.7.3-1). Run 3 exercised rollback. Restore the pre-upgrade dump, recreate at the old version, back in about 30 seconds with no re-migration and no data divergence (2026-08-31-26.7.1-to-26.7.3-3).

In-band patch hops still remove things. 26.7.2 to 26.7.3 dropped four signatures (api-removals-by-hop, finding 1). Three are admin-RBAC constants the FGAP v2 hardening took out: AdminRoles.ALL_ROLES, ALL_QUERY_ROLES and ALL_REALM_ROLES. The fourth, RepresentationToModel.OIDC, sits in keycloak-server-spi-private and never carried a compatibility promise. A custom provider naming the first three has to be checked before the version moves.

An earlier 26 line to 26.7.x. 26.0.0 goes direct, no stepping. 20 seconds to ready, index audit 119 of 119, 1,000 users intact, nothing broke (2026-08-31-26.0.0-to-26.7.3-1). The within-26 ladder is a single hop.

If you are a major behind

The path we have rehearsed is 21.1.2 to 26.7.3, stepped through 22.0.5, 23.0.7, 24.0.5 and 25.0.6. All five hops reached ready, about 139 seconds in total, 100,006 users intact (2026-08-31-21.1.2-to-26.7.3-stepped).

The index is the reason to read that record. The 21.1.2 baseline was missing idx_client_att_by_name_value before we touched it, and the schema stamp advanced through every hop anyway. An install can look migrated and be short an index. Run an index audit after the first hop instead of trusting the version number.


Written by Ben Hart at MLabs. We rehearse Keycloak upgrades against seeded datasets in a lab and publish the records. We also run these upgrades, and the certificate lifecycle around them, for teams who would rather not. Talk to us about your project.

Don't miss what's next. Subscribe to Keycloak Advisory Watch:
Powered by Buttondown, the easiest way to start and grow your newsletter.