The Keycloak Upgrade Ledger

Every upgrade we have rehearsed, with the environment stated and the clock running.

2026-08-31 · run 2026-08-31-fgap-v2-token-exchange

FGAP-v2 / token-exchange spot-check (26.7.3): activation surface changed

Condition
26.7.2/26.7.3 advisory batch — FGAP-v2 RBAC fixes (CVE-2026-14613/16105/…) and token-exchange fixes (CVE-2026-18215/18214/…)

What was checked

  1. Feature flags (serverinfo): ADMIN_FINE_GRAINED_AUTHZ_V2 enabled=true, ADMIN_FINE_GRAINED_AUTHZ enabled=false — v2 is the active line in 26.7.3.
  2. Realm activation field: PUT /admin/realms/lab with adminFineGrainedAuthz:"v2"HTTP 400 Unrecognized field "adminFineGrainedAuthz". The RealmRepresentation no longer carries this field in 26.7.3.
  3. Permission-catalog endpoint: GET /admin/realms/lab/fine-grained-permissions and /admin-fine-grained-permissions both → HTTP 404 on the lab realm.

Findings

FGAP-v2 activation surface changed in 26.7.3

Deferred (need external IdPs / dedicated harness)

← Back to the Ledger