26.6.4 (released 26 Jun 2026) is a security/bug-fix patch:
8 CVEs fixed: group-admin escalation to realm-admin (CVE-2026-9099); information disclosure via arbitrary filesystem path probing (CVE-2026-9083); XSS via case-insensitive URI validation bypass (CVE-2026-9086); disabled-client takeover via registration access token (CVE-2026-9705); privilege escalation via improper scope mapping (CVE-2026-9795); UMA permission-ticket bypass (CVE-2026-9799); policy-enforcer authorization bypass via incorrect URI comparison (CVE-2026-9800); authentication bypass via JWT algorithm confusion (CVE-2026-11800).
Enhancement: upgrade to Quarkus 3.33.2.1.
Bug fixes only (build/docs/CI hygiene).
No breaking changes; refer to the Keycloak migration guide for the full list.
Operator action required
None — drop-in patch. Same KC_DB=mariadb backend, no compose/env/config changes, no migrations beyond the standard Keycloak upgrade procedure. Verified converging + serving (HTTP 200 on /realms/master) on a direct --chaos deploy on the cc-ci swarm (dev-keycloak.ci.commoninternet.net, since torn down).
Recommended release
After this PR merges, publish the new catalogue version with:
abra recipe release keycloak -z
(patch bump — 26.6.4 is a security/bug-fix patch with no breaking changes; -z bumps 10.8.0 → 10.8.1 and tags/publishes)
Tested green on the cc-ci recipe CI server (full suite, cold, against this PR head). NOT merged — for operator review.
Recipe upgrade: keycloak/keycloak app image 26.6.3 → 26.6.4 (security patch).
## Image tag changes
| service | image | current | new |
|---------|--------------|---------|---------|
| app | keycloak/keycloak | 26.6.3 | 26.6.4 |
| db | mariadb | 12.3 | 12.3 (up-to-date, no change) |
Recipe version label is NOT bumped in this PR (left at 10.8.0+26.6.3); see the recommended release command below.
## Upstream release notes
**Upstream release notes:** app keycloak/keycloak 26.6.3→26.6.4: https://github.com/keycloak/keycloak/releases/tag/26.6.4
26.6.4 (released 26 Jun 2026) is a security/bug-fix patch:
- 8 CVEs fixed: group-admin escalation to realm-admin (CVE-2026-9099); information disclosure via arbitrary filesystem path probing (CVE-2026-9083); XSS via case-insensitive URI validation bypass (CVE-2026-9086); disabled-client takeover via registration access token (CVE-2026-9705); privilege escalation via improper scope mapping (CVE-2026-9795); UMA permission-ticket bypass (CVE-2026-9799); policy-enforcer authorization bypass via incorrect URI comparison (CVE-2026-9800); authentication bypass via JWT algorithm confusion (CVE-2026-11800).
- Enhancement: upgrade to Quarkus 3.33.2.1.
- Bug fixes only (build/docs/CI hygiene).
- No breaking changes; refer to the Keycloak migration guide for the full list.
## Operator action required
None — drop-in patch. Same KC_DB=mariadb backend, no compose/env/config changes, no migrations beyond the standard Keycloak upgrade procedure. Verified converging + serving (HTTP 200 on /realms/master) on a direct --chaos deploy on the cc-ci swarm (dev-keycloak.ci.commoninternet.net, since torn down).
## Recommended release
After this PR merges, publish the new catalogue version with:
abra recipe release keycloak -z
(patch bump — 26.6.4 is a security/bug-fix patch with no breaking changes; -z bumps 10.8.0 → 10.8.1 and tags/publishes)
Tested green on the cc-ci recipe CI server (full suite, cold, against this PR head). NOT merged — for operator review.
cc @trav @notplants
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Recipe upgrade: keycloak/keycloak app image 26.6.3 → 26.6.4 (security patch).
Image tag changes
Recipe version label is NOT bumped in this PR (left at 10.8.0+26.6.3); see the recommended release command below.
Upstream release notes
Upstream release notes: app keycloak/keycloak 26.6.3→26.6.4: https://github.com/keycloak/keycloak/releases/tag/26.6.4
26.6.4 (released 26 Jun 2026) is a security/bug-fix patch:
Operator action required
None — drop-in patch. Same KC_DB=mariadb backend, no compose/env/config changes, no migrations beyond the standard Keycloak upgrade procedure. Verified converging + serving (HTTP 200 on /realms/master) on a direct --chaos deploy on the cc-ci swarm (dev-keycloak.ci.commoninternet.net, since torn down).
Recommended release
After this PR merges, publish the new catalogue version with:
(patch bump — 26.6.4 is a security/bug-fix patch with no breaking changes; -z bumps 10.8.0 → 10.8.1 and tags/publishes)
Tested green on the cc-ci recipe CI server (full suite, cold, against this PR head). NOT merged — for operator review.
cc @trav @notplants
!testme
🌻 cc-ci —
keycloak@06338f2f✅ passedfull logs · dashboard
Auto-closed by /recipe-upgrade: its changes are already in upstream main (merged upstream); mirror main re-synced
Pull request closed