Keycloak Password-Reset Flaw Enables Unauthenticated Account Takeover

TL;DR Summary
Red Hat and Keycloak patched a critical vulnerability (CVE-2026-18963) in the reset-credentials flow that allowed an unauthenticated attacker to bypass email verification and reset any user’s password, potentially taking over accounts including admins. Upstream Keycloak is fixed in 26.7.2; Red Hat builds require 26.4.15/26.6.6 updates. As a temporary mitigation, disable the forgot-password feature across all realms; no public exploit evidence has been found yet.
Reading Insights
Total Reads
0
Unique Readers
7
Time Saved
3 min
vs 4 min read
Condensed
91%
681 → 64 words
Want the full story? Read the original article
Read on The Hacker News