CVE-2026-18963 — unauthenticated account takeover via reset-credentials flow bypass
Operator Action Required: none — patch release, no breaking changes / migrations / config changes. DB migration is automatic; back up the MariaDB volume before upgrading as a precaution.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Upgrade keycloak app 26.7.1 → 26.7.2 (patch — security + bugfix release).
Image-tag table
Recipe version label left untouched (per /recipe-upgrade convention).
What's in 26.7.2
Security patch release fixing 7 CVEs (notable account-takeover + FGAP bypasses) plus a Quarkus 3.33.3.1 upgrade:
Operator Action Required: none — patch release, no breaking changes / migrations / config changes. DB migration is automatic; back up the MariaDB volume before upgrading as a precaution.
Upstream release notes
app keycloak/keycloak 26.7.1→26.7.2: https://github.com/keycloak/keycloak/releases/tag/26.7.2
Upgrading guide: https://www.keycloak.org/docs/latest/upgrading/
Recommended release command (operator, after merge)
abra recipe release keycloak -z
Tested green on the cc-ci recipe CI server (full suite, cold, against this PR head). NOT merged — for operator review.
cc @trav @notplants
!testme
🌻 cc-ci —
keycloak@09512d37✅ passed → https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/1293(summary card unavailable — see the run for details.) full logs · dashboard
Auto-closed by /recipe-upgrade: its changes are already in upstream main (merged upstream); mirror main re-synced
Pull request closed