Red Hat Security Advisory: Red Hat build of Keycloak 26.2.6 Images Security Update
🔗 CVE IDs covered (2)
📋 Description
CVE-2025-7365 — keycloak: Phishing attack via email verification step in first login flow CVE-2025-7784 — org.keycloak/keycloak-services: Privilege Escalation in Keycloak Admin Console (FGAPv2 Enabled)
🎯 Affected products10
- Red Hat build of Keycloak 26.2
- rhbk/keycloak-operator-bundle@sha256:783a227bda4c11e067b8cc1516a04e56cb99617de7c842025caecaee5afe251d_amd64 as a component of Red Hat build of Keycloak 26.2
- rhbk/keycloak-rhel9-operator@sha256:81f301b5e1789c6f03361f5dbcb0dbd1f88ece83775e0c4c2be674646b348598_ppc64le as a component of Red Hat build of Keycloak 26.2
- rhbk/keycloak-rhel9-operator@sha256:95af515bd00e76f1d0f6140d717d910ffc239ff07efd7ad121e73d7ad554947c_amd64 as a component of Red Hat build of Keycloak 26.2
- rhbk/keycloak-rhel9-operator@sha256:9abab4c4db6badc7786466aa8bae178376a470f664bf67a1e9f212c14960e514_arm64 as a component of Red Hat build of Keycloak 26.2
- rhbk/keycloak-rhel9-operator@sha256:ff31fb18c6d17366e5b148049fd7f7f4eaf4eba6e1376ddef51cdc65b5b14018_s390x as a component of Red Hat build of Keycloak 26.2
- rhbk/keycloak-rhel9@sha256:082a1d4d0e9eb3f5de0559129c91d54726c027e7467617ed3badd2145b6ccbc2_amd64 as a component of Red Hat build of Keycloak 26.2
- rhbk/keycloak-rhel9@sha256:1a7fa57b50f718eb1b2bcfb556e07e104b150d93c0930ffdc4d46c6177a80d94_ppc64le as a component of Red Hat build of Keycloak 26.2
- rhbk/keycloak-rhel9@sha256:2a5bc5a4717543242ffb260b4e1af5cc4c7790656728d0cb8fad1e95dee14dfe_s390x as a component of Red Hat build of Keycloak 26.2
- rhbk/keycloak-rhel9@sha256:b9c24950b7961b4f9437b798e144cd2f73d75772e2eb7614b020882dedb59982_arm64 as a component of Red Hat build of Keycloak 26.2
✅ Remediation
Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. Workaround: Disable account review in the Identity Provider to prevent users from potentially modifying identity information. Disable the email verification step and use only re-authentication step. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (7)
- selfhttps://access.redhat.com/errata/RHSA-2025:12016
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2378852
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2381861
- externalhttps://issues.redhat.com/browse/RHBK-3137
- externalhttps://issues.redhat.com/browse/RHBK-3207
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_12016.json