Red Hat Security Advisory: Red Hat build of Keycloak 26.2.13 Images Security Update
🔗 CVE IDs covered (2)
📋 Description
CVE-2025-14778 — keycloak: Incorrect ownership checks in /uma-policy/ CVE-2026-1529 — org.keycloak.services.resources.organizations: Keycloak: Unauthorized organization registration via improper invitation token validation
🎯 Affected products10
- Red Hat build of Keycloak 26.2
- rhbk/keycloak-operator-bundle@sha256:e0e36e2c70b9cbb93e83c6dafc6ac90a686d1763ce2acbcedfc40903dce2d8bd_amd64 as a component of Red Hat build of Keycloak 26.2
- rhbk/keycloak-rhel9-operator@sha256:73e3d55a8873db68806fc48982d609da878cd2bb4a0f4007c2ea82bc661d506b_ppc64le as a component of Red Hat build of Keycloak 26.2
- rhbk/keycloak-rhel9-operator@sha256:a91feb3ee99a198472641b70831acdf2592d967803ca5eab281c530f64c67235_arm64 as a component of Red Hat build of Keycloak 26.2
- rhbk/keycloak-rhel9-operator@sha256:b017fe248a7101fefdf98900c015a99267c253c0c332daf9856e6eea0bbd66f3_s390x as a component of Red Hat build of Keycloak 26.2
- rhbk/keycloak-rhel9-operator@sha256:b3b19c7a73791cd1b4a8c0b3ce2f17883d75363bd7c2d460036992427d630e68_amd64 as a component of Red Hat build of Keycloak 26.2
- rhbk/keycloak-rhel9@sha256:19cbe1841b1ed82ca61c5fe824f405ecff817d515da2bc976c9170fa3a5c099c_s390x as a component of Red Hat build of Keycloak 26.2
- rhbk/keycloak-rhel9@sha256:5a199091cc3d8d218bd1877cb7e34d4c9e33110c54fcb94becd022ec25e5722b_arm64 as a component of Red Hat build of Keycloak 26.2
- rhbk/keycloak-rhel9@sha256:6b725cae2bdb6e781a1b2a3794d39c9b81458f89bb2ee13abeed52df909492b7_ppc64le as a component of Red Hat build of Keycloak 26.2
- rhbk/keycloak-rhel9@sha256:984e4a3f0d9b2e801b08fe245094f4a1871e13debf1b36fe7ca4701a3f47b570_amd64 as a component of Red Hat build of Keycloak 26.2
✅ Remediation
Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.