Official source evidenceRed HatRHSA-2026:50848
Official source article · Red Hat

RHSA-2026:50848: Vendor release notes

BlackTree keeps a versioned source snapshot and links it to relevant CVE reports. The publisher remains authoritative for product applicability, release details and installation guidance.

Read the official article ↗
PublisherRed Hat
Article IDRHSA-2026:50848
Verified snapshot29 Sept 2026, 02:41 UTC
Linked CVEs10

Linked CVE reports

These are source relationships, not a claim that this article fixes every affected product or branch.

  • CVE-2026-16100Keycloak-services: keycloak-services: unbounded metric cardinality in user event metrics via request-controlled error text
  • CVE-2026-16443Keycloak-services: keycloak-services: saml broker metadata import disables response signature validation
  • CVE-2026-16442Keycloak-services: keycloak-services: saml idp-initiated broker login bypasses link-only restriction
  • CVE-2026-16071Keycloak-services: keycloak-services: ldap entry-dn user search bypasses configured users dn boundary
  • CVE-2026-16102Keycloak-services: keycloak-services: default dcr policy allows role forgery via user property mappers
  • CVE-2026-15573Keycloak-services: keycloak-services: authorization bypass via unnormalized uri matching in pathmatcher
  • CVE-2026-11986Keycloak-rest-admin-ui-ext: authorization bypass vulnerability in the admin-ui-ext bulk role-mapping-delete endpoints of keycloak
  • CVE-2026-14615Keycloak-services: keycloak: fgap v2 parent group children endpoint bypasses per-child view permission filter
  • CVE-2026-14614Keycloak-services: keycloak-services: fgap v2 client scope assignment bypass via clientresource
  • CVE-2026-15572Keycloak-services: keycloak-services: dcr protocol mapper type-swap policy bypass allows privilege escalation

Source and provenance

Original title: Vendor release notes. Captured 29 Sept 2026, 02:41 UTC. The stored article is used for enrichment and change detection; BlackTree does not republish the publisher's full text here.

Open the publisher's current version ↗