Keycloak 26.7.4 (security update)
The release 26.7.4 of Keycloak is available on Clever Cloud. It’s a security update that addresses six vulnerabilities, without any critical one.
CVE-2026-74909, rated 8.1, is an incomplete fix: a percent-encoded semicolon in a request path bypasses the matrix parameters stripping of the policy enforcer and grants access to protected resources. CVE-2026-79651, rated 7.5, lets an unauthenticated attacker exhaust memory through the theme localization endpoints. CVE-2026-17526, rated 7.2, allows a user holding the impersonation role to impersonate a realm administrator.
The other fixes address CVE-2026-18212, CVE-2026-90997 and CVE-2026-19607, affecting SAML Redirect binding, replay protection on MySQL and MariaDB, and an account lockout in the first broker login flow.
Authorization Services now normalize resource URIs before matching them. They strip matrix parameters, resolve dot segments, decode %2F, and drop the trailing slash, query string and fragment. If your resources rely on these elements to differ, review their URIs before you update. The release also upgrades Quarkus to 3.33.3.2 and fixes performance issues introduced in 26.6.2, an Admin Console error when you select a subgroup and a startup crash with the Oracle OCI driver.
Update through the add-on’s dashboard in the Clever Cloud Console. You can also set CC_KEYCLOAK_VERSION of the underlying Java application to 26.7.4 and rebuild it, or use Clever Tools:
clever features enable operators
clever keycloak version check yourKeycloakNameOrId --format json
clever keycloak version update yourKeycloakNameOrId --target 26.7.4
