# Keycloak 26.4.1 released

DevFeed: [Keycloak 26.4.1 released](<https://devfeed.tech/articles/keycloak-26-4-1-released-31727.md>)

Original publisher: [Read original article](<https://www.keycloak.org/2025/10/keycloak-2641-released>)

Author: Keycloak Team

Published: 2025-10-16T00:00:00Z

Content type: release

Language: en

Sources: [Keycloak Blog](<https://devfeed.tech/sources/keycloak-blog.md>)

Topics: [Keycloak](<https://devfeed.tech/topics/keycloak.md>), [releases](<https://devfeed.tech/topics/releases.md>), [Release notes](<https://devfeed.tech/topics/release-notes.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [idm](<https://devfeed.tech/tags/idm.md>), [jwt](<https://devfeed.tech/tags/jwt.md>), [kerberos](<https://devfeed.tech/tags/kerberos.md>), [keycloak](<https://devfeed.tech/tags/keycloak.md>), [keycloak-release](<https://devfeed.tech/tags/keycloak-release.md>), [ldap](<https://devfeed.tech/tags/ldap.md>), [oidc](<https://devfeed.tech/tags/oidc.md>), [openid-connect](<https://devfeed.tech/tags/openid-connect.md>), [race-condition](<https://devfeed.tech/tags/race-condition.md>), [release](<https://devfeed.tech/tags/release.md>), [release-notes](<https://devfeed.tech/tags/release-notes.md>), [saml](<https://devfeed.tech/tags/saml.md>), [security](<https://devfeed.tech/tags/security.md>), [sso](<https://devfeed.tech/tags/sso.md>)

## AI overview

Keycloak 26.4.1 is released with a new security-related feature, enhancements, and fixes across authentication, authorization, administration, user profiles, LDAP, documentation, sessions, and other components.

## Source excerpt

To download the release go to Keycloak downloads. Upgrading Before upgrading refer to the migration guide for a complete list of changes. All resolved issues New features #43020 Secure Client-Initiated Renegotiation - disable by default dist/quarkus Enhancements #42990 Hide read-only email attribute in update profile context with update email enabled user-profile #43357 JDBC_PING should publish its physical address on startup Bugs #40965 Group permission denies to view user admin/fine-grained-permissions #41292 openid-connect flow is missing response type on language change authentication #42565 Standard Token Exchange: chain of exchanges eventually fails token-exchange #42676 Security Defenses realm settings lost when switching between Headers and Brute Force Detection tabs (v25+) admin/ui #42907 Race condition in authorization service leads to NullPointerException when evaluating permissions during concurrent resource deletion authorization-services #43042 Avoid NPE in FederatedJWTClientAuthenticator when checking for supported assertion types core #43070 Update email page with pending verification email messages prefilled with old email user-profile #43096 keycloak-operator 26.4.0 missing clusterrole permissions docs #43104 Release notes fix for update email docs #43161 Restarting an user session broken for persistent sessions infinispan #43164 Keycloak docs state that only TLSv1.3 is used docs #43218 Cannot revoke access token generated by Standard Token Exchange oidc #43254 Make sure username and email attributes are lower cased when fetching their values from LDAP object ldap #43269 Keycloak 26.4 returns a different error response on a token request without Client Assertion (private_key_jwt client authentication) from Keycloak 26.3 does oidc #43270 Keycloak 26.4 returns a different error response on a CIBA backchannel authentication request without Client Assertion (private_key_jwt client authentication) from Keycloak 26.3 does oidc #43286 Broken links on DB s