RHSA-2026:68276HighCVSS 8.1

Red Hat Security Advisory: Red Hat build of Keycloak 26.4.16 Images Security Update

Published
September 16, 2026
Last Modified
September 21, 2026

🔗 CVE IDs covered (7)

📋 Description

CVE-2026-17526 — keycloak-services: keycloak-services: Privilege escalation via impersonation role allows takeover of realm administrator accounts CVE-2026-18212 — keycloak-services: keycloak-services: SAML Redirect DEFLATE helpers leak native zlib state CVE-2026-19607 — keycloak-services: keycloak-services: Broker-originated username collision causes account lockout CVE-2026-19729 — keycloak-services: keycloak-services: Incomplete fix for arbitrary filesystem path probing via keystore parameters CVE-2026-62243 — io.netty/netty-handler: Netty: TLS hostname verification bypass via OpenSSL client path misconfiguration CVE-2026-74909 — keycloak-services: keycloak-services: Incomplete fix for CVE-2026-15573 allows policy enforcer bypass via percent-encoded URI segments CVE-2026-79651 — keycloak-services: keycloak-services: unauthenticated DoS via unbounded locale caching

🎯 Affected products10

  • Red Hat build of Keycloak 26.4
  • rhbk/keycloak-operator-bundle@sha256:f9f87b578925a866bb0a6eb85b96fc4d40d7a76508bcc042c47a870e038185d0_amd64 as a component of Red Hat build of Keycloak 26.4
  • rhbk/keycloak-rhel9-operator@sha256:62295b1297796d71b1ae80dff660fa806915967fdbce2ed6b69bd6dd0d949970_arm64 as a component of Red Hat build of Keycloak 26.4
  • rhbk/keycloak-rhel9-operator@sha256:7f0849b3093db0b70f2448013d8960ffcc080465f09d7db3c0fe8f16c8ffe7a0_ppc64le as a component of Red Hat build of Keycloak 26.4
  • rhbk/keycloak-rhel9-operator@sha256:ba3dd6e11edd6da59f652f3c1ba1d015e93dfd61986c048750dd8b25556795b3_s390x as a component of Red Hat build of Keycloak 26.4
  • rhbk/keycloak-rhel9-operator@sha256:e108c6d85a4e70d52f7e6eda39e59cef9fbabea9412b08a9da0fec686da70615_amd64 as a component of Red Hat build of Keycloak 26.4
  • rhbk/keycloak-rhel9@sha256:0645b67de8c23ae9357ee892c6a9b61760f6d28f05d354b8916fe57b4534e628_ppc64le as a component of Red Hat build of Keycloak 26.4
  • rhbk/keycloak-rhel9@sha256:32ef9228f43a5d3bad7ce8916cd1170bd84573c03cb7e5f4e1c0da67813a21a6_arm64 as a component of Red Hat build of Keycloak 26.4
  • rhbk/keycloak-rhel9@sha256:75d039cf9da1facdf35deb724d82568cd23e2a059b6d5cb6944a39cca45c3cff_s390x as a component of Red Hat build of Keycloak 26.4
  • rhbk/keycloak-rhel9@sha256:967602076c4b0b80ab059470845af9656375deaf115c9f787b25514b5d3b6023_amd64 as a component of Red Hat build of Keycloak 26.4

✅ Remediation

Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: This vulnerability only affects applications that explicitly configure Netty to use the OpenSSL TLS provider (SslProvider.OPENSSL). The following mitigations can reduce exposure without applying a patch: 1) Use the default JDK SSL provider — Do not configure SslProvider.OPENSSL in your Netty SslContext setup. The default JDK SSL provider (SslProvider.JDK) is not affected by this vulnerability. Most applications use the JDK default unless explicitly overridden. 2) Use X509ExtendedTrustManager — If the OpenSSL provider is required, ensure the configured trust manager extends X509ExtendedTrustManager rather than the plain X509TrustManager interface. The extended variant performs hostname verification independently of the Netty wrapping logic. 3) Run on Java 24 or earlier — The vulnerable code path only triggers on Java 25+ where sun.misc.Unsafe-based trust-manager wrapping is unavailable. Running on earlier Java versions (e.g., Java 21 LTS) means the wrapping works correctly and hostname verification stays enabled.

🔗 References (3)