# Keycloak 26.5.6 released

DevFeed: [Keycloak 26.5.6 released](<https://devfeed.tech/articles/keycloak-26-5-6-released-31762.md>)

Original publisher: [Read original article](<https://www.keycloak.org/2026/03/keycloak-2656-released>)

Author: Keycloak Team

Published: 2026-03-19T00:00:00Z

Content type: release

Language: en

Sources: [Keycloak Blog](<https://devfeed.tech/sources/keycloak-blog.md>)

Topics: [Keycloak](<https://devfeed.tech/topics/keycloak.md>), [Security](<https://devfeed.tech/topics/security.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>), [OpenID connect (OIDC)](<https://devfeed.tech/topics/oidc.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [access-control](<https://devfeed.tech/tags/access-control.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [idm](<https://devfeed.tech/tags/idm.md>), [kerberos](<https://devfeed.tech/tags/kerberos.md>), [keycloak](<https://devfeed.tech/tags/keycloak.md>), [keycloak-release](<https://devfeed.tech/tags/keycloak-release.md>), [ldap](<https://devfeed.tech/tags/ldap.md>), [oidc](<https://devfeed.tech/tags/oidc.md>), [openid-connect](<https://devfeed.tech/tags/openid-connect.md>), [race-condition](<https://devfeed.tech/tags/race-condition.md>), [release](<https://devfeed.tech/tags/release.md>), [saml](<https://devfeed.tech/tags/saml.md>), [security](<https://devfeed.tech/tags/security.md>), [spiffe](<https://devfeed.tech/tags/spiffe.md>), [sso](<https://devfeed.tech/tags/sso.md>)

## AI overview

Keycloak 26.5.6 was released on March 19, 2026. The release includes security fixes for issues including SSRF, refresh-token reuse bypass, improper access control, privilege escalation, authorization bypass, and information disclosure, along with other bug fixes.

## Source excerpt

To download the release go to Keycloak downloads. Upgrading Before upgrading refer to the migration guide for a complete list of changes. All resolved issues Security fixes #45645 CVE-2026-1180 - Blind Server-Side Request Forgery (SSRF) in Keycloak OIDC Dynamic Client Registration via jwks_uri oidc #45647 CVE-2026-1035 - Keycloak Refresh Token Reuse Bypass via TOCTOU Race Condition oidc #45650 CVE-2025-14777 - Keycloak IDOR in realm client creating/deleting #45653 CVE-2025-14082 keycloak-server: Keycloak Admin REST API: Improper Access Control leads to sensitive role metadata information disclosure #46719 CVE-2026-3121 - Keycloak: Privilege escalation via manage-clients permission #46723 CVE-2026-3190 - Information Disclosure via improper role enforcement in UMA 2.0 Protection API core #46922 CVE-2026-3911 Keycloak: Information disclosure of disabled user attributes via administrative endpoint user-profile #47062 CVE-2026-2366 Authorization Bypass: Unprivileged tokens can enumerate user organization memberships organizations Bugs #45889 Federated user disabled when external DB unavailable, never re-enabled storage #46239 AUTH_SESSION_ID cookie reuse causes cross-user session contamination on re-authentication authentication #46296 UsersResource.search briefRepresentation started to return user attributes admin/api #46379 Unexpected error when logging out with offline session and external IDP oidc #46459 Operator-built DB config: targetServerType=primary not applied / connection validation not working after master-replica failover (26.5.0) operator #46588 Partial LDAP sync duration does not follow the defined value in user federation ldap #46605 26.5.4 startup regression with many realms: RealmCacheSession.prepareCachedRealm() scans master admin role composites per realm (O(N²)) core #46656 Em-Hyphens in SPI options on cache configuration page docs #46663 JGroups bind port configuration ignored when --cache-embedded-network-bind-port set infinispan #46669 SPIFFE Clie