Chapter 6. Updates for 26.2.13
This release contains several fixed issues and changes related to upgrading. For details, see the Upgrading Guide.
6.1. CVE fixes Copy linkLink copied to clipboard!
Copy linkLink copied to clipboard!
- CVE-2025-14778 A Broken Access Control vulnerability exists in the UserManagedPermissionService (UMA Protection API).
- CVE-2026-1529 Organization invitation tokens in Keycloak are parsed without cryptographic signature verification during the registration flow.